CVE-2022-3977

CVSS V2 None CVSS V3 None
Description
A use-after-free flaw was found in the Linux kernel MCTP (Management Component Transport Protocol) functionality. This issue occurs when a user simultaneously calls DROPTAG ioctl and socket close happens, which could allow a local user to crash the system or potentially escalate their privileges on the system.
Overview
  • CVE ID
  • CVE-2022-3977
  • Assigner
  • secalert@redhat.com
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2023-01-12T19:15:24
  • Last Modified Date
  • 2023-04-11T18:15:32
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:o:linux:linux_kernel:6.1:rc1:*:*:*:*:*:* 1 OR
History
Created Old Value New Value Data Type Notes
2023-01-12 20:16:14 Added to TrackCVE
2023-01-12 20:16:16 Weakness Enumeration new
2023-01-19 01:14:19 Awaiting Analysis Undergoing Analysis Vulnerability Status updated
2023-01-23 15:13:58 2023-01-23T15:12:53 CVE Modified Date updated
2023-01-23 15:13:58 Undergoing Analysis Analyzed Vulnerability Status updated
2023-01-23 15:13:59 CPE Information updated
2023-02-23 20:14:04 2023-02-23T19:15:11 CVE Modified Date updated
2023-02-23 20:14:04 Analyzed Modified Vulnerability Status updated
2023-02-23 20:14:05 References updated
2023-04-11 21:16:43 2023-04-11T18:15:32 CVE Modified Date updated
2023-04-11 21:16:43 Modified Analyzed Vulnerability Status updated