From 157fb8dc9e1e29eec4ee70c76df6685db6980c3c Mon Sep 17 00:00:00 2001 From: Salvatore Bonaccorso Date: Wed, 8 Jun 2022 08:38:39 +0200 Subject: Add CVE-2022-1998 --- active/CVE-2022-1998 | 17 +++++++++++++++++ 1 file changed, 17 insertions(+) create mode 100644 active/CVE-2022-1998 diff --git a/active/CVE-2022-1998 b/active/CVE-2022-1998 new file mode 100644 index 00000000..413c8d51 --- /dev/null +++ b/active/CVE-2022-1998 @@ -0,0 +1,17 @@ +Description: fanotify: Fix stale file descriptor in copy_event_to_user() +References: + https://bugzilla.redhat.com/show_bug.cgi?id=2052312 +Notes: + carnil> CAP_SYS_ADMIN capability is required to exploit the issue. + carnil> Issue introduced with f644bc449b37 ("fanotify: fix + carnil> copy_event_to_user() fid error clean up") in 5.13-rc7 and was + carnil> backported to 5.10.46 and 5.12.13. +Bugs: +upstream: released (5.17-rc3) [ee12595147ac1fbfb5bcb23837e26dd58d94b15d] +5.10-upstream-stable: released (5.10.97) [7b4741644cf718c422187e74fb07661ef1d68e85] +4.19-upstream-stable: N/A "Vulnerable code not present" +4.9-upstream-stable: N/A "Vulnerable code not present" +sid: released (5.16.7-1) +5.10-bullseye-security: released (5.10.103-1) +4.19-buster-security: N/A "Vulnerable code not present" +4.9-stretch-security: N/A "Vulnerable code not present" -- cgit v1.2.3