CVE-2022-1419

Updated: 2023-11-04 21:02:21.149136

Description:

The root cause of this vulnerability is that the ioctl$DRM_IOCTL_MODE_DESTROY_DUMB can decrease refcount of *drm_vgem_gem_object *(created in *vgem_gem_dumb_create*) concurrently, and *vgem_gem_dumb_create *will access the freed drm_vgem_gem_object.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x MEDIUM 4.6
CVSS Version 3.x HIGH 7.8

Status

OS name Project name Version Score Severity Status Errata Last updated
CentOS 6 ELS kernel 2.6.32 7.8 HIGH Not Vulnerable 2022-09-07 11:05:13
CentOS 7 ELS kernel 3.10.0 7.8 HIGH Needs Triage 2023-09-18 17:07:22
CentOS 8.4 ELS kernel 4.18.0 7.8 HIGH Not Vulnerable 2022-09-07 11:05:13
CentOS 8.5 ELS kernel 4.18.0 7.8 HIGH Not Vulnerable 2022-09-07 11:05:13
CloudLinux 6 ELS kernel 2.6.32 7.8 HIGH Not Vulnerable 2022-09-07 11:05:13
Oracle Linux 6 ELS kernel 2.6.32 7.8 HIGH Not Vulnerable 2022-09-07 11:05:13
Ubuntu 16.04 ELS linux 4.4.0 7.8 HIGH Released CLSA-2022:1667414297 2022-11-02 17:05:48
Ubuntu 16.04 ELS linux-hwe 4.15.0 7.8 HIGH Released CLSA-2022:1664906081 2022-10-04 14:02:48
Ubuntu 18.04 ELS linux 4.15.0 7.8 HIGH Already Fixed 2023-06-02 09:10:36