The SUNRPC subsystem in the Linux kernel through 5.17.2 can call xs_xprt_free before ensuring that sockets are in the intended state.
References
| Link | Resource |
|---|---|
| https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=1a3b1bba7c7a5eb8a11513cf88427cb9d77bc60a | Patch Third Party Advisory |
| http://www.openwall.com/lists/oss-security/2022/04/11/4 | Issue Tracking Mailing List Patch |
| http://www.openwall.com/lists/oss-security/2022/04/11/3 | Mailing List Patch Third Party Advisory |
| http://www.openwall.com/lists/oss-security/2022/04/11/5 | Mailing List Patch Third Party Advisory |
| https://security.netapp.com/advisory/ntap-20220526-0002/ | |
| https://www.debian.org/security/2022/dsa-5161 |
Configurations
Information
Published : 2022-04-11 05:15
Updated : 2022-06-13 11:15
NVD link : CVE-2022-28893
Mitre link : CVE-2022-28893
JSON object : View
Products Affected
linux
- linux_kernel
CWE
CWE-416
Use After Free
