CVE-2022-40768

Updated: 2025-08-20 00:03:37.925028

Description:

drivers/scsi/stex.c in the Linux kernel through 5.19.9 allows local users to obtain sensitive information from kernel memory because stex_queuecommand_lck lacks a memset for the PASSTHRU_CMD case.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x MEDIUM 5.5

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU kernel 5.14.0 5.5 MEDIUM Ignored 2023-11-21 04:12:09 This bug only affects the Promise SuperTrak EX hardware RAID driver (stex); systems without that con...
CentOS 6 ELS kernel 2.6.32 5.5 MEDIUM Ignored 2022-09-22 05:02:20 Ignored due to low severity
CentOS 7 ELS kernel 3.10.0 5.5 MEDIUM Ignored 2023-09-19 05:07:36 Ignored due to low severity
CentOS 8.4 ELS kernel 4.18.0 5.5 MEDIUM Ignored 2022-09-22 05:02:20 Ignored due to low severity
CentOS 8.5 ELS kernel 4.18.0 5.5 MEDIUM Ignored 2022-09-22 05:02:20 Ignored due to low severity
CloudLinux 6 ELS kernel 2.6.32 5.5 MEDIUM Ignored 2022-09-22 05:02:20 Ignored due to low severity
Oracle Linux 6 ELS kernel 2.6.32 5.5 MEDIUM Ignored 2022-09-22 05:02:20 Ignored due to low severity
Ubuntu 16.04 ELS linux-hwe 4.15.0 5.5 MEDIUM Released CLSA-2022:1670263674 2022-12-05 16:04:16
Ubuntu 16.04 ELS linux 4.4.0 5.5 MEDIUM Released CLSA-2022:1670261781 2022-12-05 13:04:19
Ubuntu 18.04 ELS linux 4.15.0 5.5 MEDIUM Released 2023-11-07 03:57:43