cbcvebase.
CVE-2022-3176
published 2022-09-16

CVE-2022-3176: There exists a use-after-free in io_uring in the Linux kernel. Signalfd_poll() and binder_poll() use a waitqueue whose lifetime is the current task. It will…

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
There exists a use-after-free in io_uring in the Linux kernel. Signalfd_poll() and binder_poll() use a waitqueue whose lifetime is the current task. It will send a POLLFREE notification to all waiters before the queue is freed. Unfortunately, the io_uring poll doesn't handle POLLFREE. This allows a use-after-free to occur if a signalfd or binder fd is polled with io_uring poll, and the waitqueue gets freed. We recommend upgrading past commit fc78b2fc21f10c4c9c4d5d659a685710ffa63659

Affected

14 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianlinux< linux 5.17.3-1 (bookworm)linux 5.17.3-1 (bookworm)
linuxkernel>= unspecified < fc78b2fc21f10c4c9c4d5d659a685710ffa63659fc78b2fc21f10c4c9c4d5d659a685710ffa63659
linuxlinux_kernel>= 0 < 5.10.149-15.10.149-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 0 < 5.17.3-15.17.3-1
linuxlinux_kernel>= 0 < 5.4.0-128.1445.4.0-128.144
linuxlinux_kernel>= 0 < 5.15.0-50.565.15.0-50.56
linuxlinux_kernel>= 5.1 < 5.4.2125.4.212
linuxlinux_kernel>= 5.11 < 5.15.655.15.65
linuxlinux_kernel>= 5.16 < 5.175.17
linuxlinux_kernel>= 5.5 < 5.10.1415.10.141

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH