CVE-2022-24448

Updated: 2023-11-07 19:01:49.793174

Description:

An issue was discovered in fs/nfs/dir.c in the Linux kernel before 5.16.5. If an application sets the O_DIRECTORY flag, and tries to open a regular file, nfs_atomic_open() performs a regular lookup. If a regular file is found, ENOTDIR should occur, but the server instead returns uninitialized data in the file descriptor.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x LOW 1.9
CVSS Version 3.x LOW 3.3

Status

OS name Project name Version Score Severity Status Errata Last updated
AlmaLinux 9.2 ESU kernel 5.14.0 3.3 LOW Ignored 2023-11-08 04:07:56
AlmaLinux 9.2 FIPS kernel 5.14.0 3.3 LOW Ignored 2023-11-21 04:12:29
CentOS 6 ELS kernel 2.6.32 3.3 LOW Ignored 2022-05-05 16:13:26
CentOS 7 ELS kernel 3.10.0 3.3 LOW Ignored 2023-09-19 09:30:22
CentOS 8.4 ELS kernel 4.18.0 3.3 LOW Ignored 2022-12-02 20:04:35
CentOS 8.5 ELS kernel 4.18.0 3.3 LOW Ignored 2022-12-02 20:04:18
CloudLinux 6 ELS kernel 2.6.32 3.3 LOW Ignored 2022-05-05 16:13:26
Oracle Linux 6 ELS kernel 2.6.32 3.3 LOW Ignored 2022-05-05 16:13:26
Ubuntu 16.04 ELS linux-hwe 4.15.0 3.3 LOW Ignored 2022-09-28 08:02:29
Ubuntu 16.04 ELS linux 4.4.0 3.3 LOW Released CLSA-2023:1684277390 2023-05-16 21:28:23
Total: 11