cbcvebase.
CVE-2022-1678
published 2022-05-25

CVE-2022-1678: An issue was discovered in the Linux Kernel from 4.18 to 4.19, an improper update of sock reference in TCP pacing can lead to memory/netns leak, which can be…

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
An issue was discovered in the Linux Kernel from 4.18 to 4.19, an improper update of sock reference in TCP pacing can lead to memory/netns leak, which can be used by remote clients.

Affected

9 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.2.6-1 (bookworm)linux 5.2.6-1 (bookworm)
linuxlinux_kernel>= 0 < 5.2.6-15.2.6-1
linuxlinux_kernel>= 0 < 5.2.6-15.2.6-1
linuxlinux_kernel>= 0 < 5.2.6-15.2.6-1
linuxlinux_kernel>= 0 < 5.2.6-15.2.6-1
linuxlinux_kernel>= 4.18 < unspecifiedunspecified
linuxlinux_kernel4.18 – 4.19
linuxlinux_kernelunspecified – 4.19
netappe-series_santricity_os_controller11.0 – 11.70.2

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH