summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorSalvatore Bonaccorso <carnil@debian.org>2022-06-08 08:38:39 +0200
committerSalvatore Bonaccorso <carnil@debian.org>2022-06-08 08:39:12 +0200
commit157fb8dc9e1e29eec4ee70c76df6685db6980c3c (patch)
tree58826284b9c7996719c2a457a14479d72cc3e818
parenta47574bcdfdf0d68e1e46e90f9ffa15857032b67 (diff)
Add CVE-2022-1998
-rw-r--r--active/CVE-2022-199817
1 files changed, 17 insertions, 0 deletions
diff --git a/active/CVE-2022-1998 b/active/CVE-2022-1998
new file mode 100644
index 00000000..413c8d51
--- /dev/null
+++ b/active/CVE-2022-1998
@@ -0,0 +1,17 @@
+Description: fanotify: Fix stale file descriptor in copy_event_to_user()
+References:
+ https://bugzilla.redhat.com/show_bug.cgi?id=2052312
+Notes:
+ carnil> CAP_SYS_ADMIN capability is required to exploit the issue.
+ carnil> Issue introduced with f644bc449b37 ("fanotify: fix
+ carnil> copy_event_to_user() fid error clean up") in 5.13-rc7 and was
+ carnil> backported to 5.10.46 and 5.12.13.
+Bugs:
+upstream: released (5.17-rc3) [ee12595147ac1fbfb5bcb23837e26dd58d94b15d]
+5.10-upstream-stable: released (5.10.97) [7b4741644cf718c422187e74fb07661ef1d68e85]
+4.19-upstream-stable: N/A "Vulnerable code not present"
+4.9-upstream-stable: N/A "Vulnerable code not present"
+sid: released (5.16.7-1)
+5.10-bullseye-security: released (5.10.103-1)
+4.19-buster-security: N/A "Vulnerable code not present"
+4.9-stretch-security: N/A "Vulnerable code not present"

© 2014-2024 Faster IT GmbH | imprint | privacy policy