CVE-2022-47946

CVSS V2 None CVSS V3 None
Description
An issue was discovered in the Linux kernel 5.10.x before 5.10.155. A use-after-free in io_sqpoll_wait_sq in fs/io_uring.c allows an attacker to crash the kernel, resulting in denial of service. finish_wait can be skipped. An attack can occur in some situations by forking a process and then quickly terminating it. NOTE: later kernel versions, such as the 5.15 longterm series, substantially changed the implementation of io_sqpoll_wait_sq.
Overview
  • CVE ID
  • CVE-2022-47946
  • Assigner
  • cve@mitre.org
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2022-12-23T22:15:08
  • Last Modified Date
  • 2023-01-04T20:06:58
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 1 OR 5.10 5.10.155
History
Created Old Value New Value Data Type Notes
2022-12-23 23:15:03 Added to TrackCVE
2022-12-25 02:16:02 2022-12-25T02:07:49 CVE Modified Date updated
2022-12-25 02:16:02 Received Awaiting Analysis Vulnerability Status updated
2022-12-27 13:15:42 2022-12-27T13:15:11 CVE Modified Date updated
2022-12-27 13:15:44 References updated
2022-12-29 15:13:51 Awaiting Analysis Undergoing Analysis Vulnerability Status updated
2022-12-29 19:14:28 Undergoing Analysis Awaiting Analysis Vulnerability Status updated
2022-12-29 20:15:00 Awaiting Analysis Undergoing Analysis Vulnerability Status updated
2023-01-04 20:15:09 2023-01-04T20:06:58 CVE Modified Date updated
2023-01-04 20:15:09 Undergoing Analysis Analyzed Vulnerability Status updated
2023-01-04 20:15:09 Weakness Enumeration new
2023-01-04 20:15:10 CPE Information updated