CVE-2022-0882
published 2022-05-03CVE-2022-0882: A bug exists where an attacker can read the kernel log through exposed Zircon kernel addresses without the required capability ZX_RSRC_KIND_ROOT. It is…
PriorityP422medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.11%
1.9th percentile
A bug exists where an attacker can read the kernel log through exposed Zircon kernel addresses without the required capability ZX_RSRC_KIND_ROOT. It is recommended to upgrade the Fuchsia kernel to 4.1.1 or greater.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fuchsia | < 4.1.1 | 4.1.1 | |
| google_llc | fuchsia_kernel | >= unspecified < 4.1.1 | 4.1.1 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gqmg-mqmp-6h9h: A bug exists where an attacker can read the kernel log through exposed Zircon kernel addresses without the required capability ZX_RSRC_KIND_ROOT
ghsa_unreviewed·2022-05-04
CVE-2022-0882 [MEDIUM] CWE-200 GHSA-gqmg-mqmp-6h9h: A bug exists where an attacker can read the kernel log through exposed Zircon kernel addresses without the required capability ZX_RSRC_KIND_ROOT
A bug exists where an attacker can read the kernel log through exposed Zircon kernel addresses without the required capability ZX_RSRC_KIND_ROOT. It is recommended to upgrade the Fuchsia kernel to 4.1.1 or greater.
Red Hat
vim: use-after-free in did_set_spelllang() in src/spell.c
vendor_redhat·2022-12-02·CVSS 7.8
CVE-2022-4292 [HIGH] CWE-416 vim: use-after-free in did_set_spelllang() in src/spell.c
vim: use-after-free in did_set_spelllang() in src/spell.c
Use After Free in GitHub repository vim/vim prior to 9.0.0882.
A heap use-after-free flaw was found in Vim's did_set_spelllang() function of the spell.c file. This issue occurs because vim uses freed memory after SpellFileMissing autocmd uses bwipe. This could allows an attacker to trick a user into opening a specially crafted file, triggering a heap use-after-free issue that causes an application to crash, possibly executing code and corrupting memory.
Statement: Red Hat Product Security has rated this issue as having a Low security impact, because the "victim" has to run an untrusted file in script mode.
For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classifica
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-05-03
Published