CVE-2022-29156Double Free in Kernel

Severity
7.8HIGHNVD
OSV5.6
EPSS
0.1%
top 65.96%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 13
Latest updateJan 22

Description

drivers/infiniband/ulp/rtrs/rtrs-clt.c in the Linux kernel before 5.16.12 has a double free related to rtrs_clt_dev_release.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages5 packages

NVDlinux/linux_kernel5.10.205.10.103+2
Debianlinux/linux_kernel< 5.10.103-1+3
debiandebian/linux< linux 5.16.12-1 (bookworm)

Patches

🔴Vulnerability Details

3
OSV
linux, linux-aws, linux-aws-5.13, linux-azure, linux-azure-5.13, linux-gcp, linux-gcp-5.13, linux-hwe-5.13, linux-kvm, linux-oracle, linux-raspi vulnerabilities2022-05-12
GHSA
GHSA-3mww-r5c8-cgph: drivers/infiniband/ulp/rtrs/rtrs-clt2022-04-14
OSV
CVE-2022-29156: drivers/infiniband/ulp/rtrs/rtrs-clt2022-04-13

📋Vendor Advisories

4
Ubuntu
Linux kernel vulnerabilities2022-05-12
Red Hat
kernel: rtrs-clt.c rtrs_clt_dev_release double free2022-04-13
Microsoft
drivers/infiniband/ulp/rtrs/rtrs-clt.c in the Linux kernel before 5.16.12 has a double free related to rtrs_clt_dev_release.2022-04-12
Debian
CVE-2022-29156: linux - drivers/infiniband/ulp/rtrs/rtrs-clt.c in the Linux kernel before 5.16.12 has a ...2022

📄Research Papers

1
arXiv
SyzRetrospector: A Large-Scale Retrospective Study of Syzbot2024-01-22