cbcvebase.
CVE-2022-4379
published 2023-01-10

CVE-2022-4379: A use-after-free vulnerability was found in __nfs42_ssc_open() in fs/nfs/nfs4file.c in the Linux kernel. This flaw allows an attacker to conduct a remote denial

PriorityP346high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
6.35%
92.9th percentile
A use-after-free vulnerability was found in __nfs42_ssc_open() in fs/nfs/nfs4file.c in the Linux kernel. This flaw allows an attacker to conduct a remote denial

Affected

16 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.4-1 (bookworm)linux 6.1.4-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 5.15.0-67.745.15.0-67.74
linuxlinux_kernel>= 5.11 < 5.15.1055.15.105
linuxlinux_kernel>= 5.16 < 6.1.36.1.3
linuxlinux_kernel>= 5.6 < 5.10.1775.10.177
msrccbl2_hyperv-daemons_5.15.87.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.107.1-2_on_cbl_mariner_2.0
msrccm1_hyperv-daemons_5.10.174.1-1_on_cbl_mariner_1.0
msrccm1_kernel_5.10.177.1-1_on_cbl_mariner_1.0

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.