cbcvebase.
CVE-2022-48771
published 2024-06-20

CVE-2022-48771: In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Fix stale file descriptors on failed usercopy A failing usercopy of the…

PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.21%
11.7th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Fix stale file descriptors on failed usercopy A failing usercopy of the fence_rep object will lead to a stale entry in the file descriptor table as put_unused_fd() won't release it. This enables userland to refer to a dangling 'file' object through that still valid file descriptor, leading to all kinds of use-after-free exploitation scenarios. Fix this by deferring the call to fd_install() until after the usercopy has succeeded.

Affected

24 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.16.7-1 (bookworm)linux 5.16.7-1 (bookworm)
googlegoogle-protobuf>= 0 < 3.16.33.16.3
googlegoogle-protobuf>= 3.17.0.rc.1 < 3.19.63.19.6
googlegoogle-protobuf>= 3.20.0.rc.1 < 3.20.33.20.3
googlegoogle-protobuf>= 3.21.0.rc.1 < 3.21.73.21.7
linuxlinux
linuxlinux>= c906965dee22d5e95d0651759ba107b420212a9f < e8d092a62449dcfc73517ca43963d2b8f44d0516e8d092a62449dcfc73517ca43963d2b8f44d0516
linuxlinux>= c906965dee22d5e95d0651759ba107b420212a9f < 0008a0c78fc33a84e2212a7c04e6b21a36ca6f4d0008a0c78fc33a84e2212a7c04e6b21a36ca6f4d
linuxlinux>= c906965dee22d5e95d0651759ba107b420212a9f < 84b1259fe36ae0915f3d6ddcea6377779de48b8284b1259fe36ae0915f3d6ddcea6377779de48b82
linuxlinux>= c906965dee22d5e95d0651759ba107b420212a9f < ae2b20f27732fe92055d9e7b350abc5cdf3e2414ae2b20f27732fe92055d9e7b350abc5cdf3e2414
linuxlinux>= c906965dee22d5e95d0651759ba107b420212a9f < 6066977961fc6f437bc064f628cf9b0e4571c56c6066977961fc6f437bc064f628cf9b0e4571c56c
linuxlinux>= c906965dee22d5e95d0651759ba107b420212a9f < 1d833b27fb708d6fdf5de9f6b3a8be4bd43215651d833b27fb708d6fdf5de9f6b3a8be4bd4321565
linuxlinux>= c906965dee22d5e95d0651759ba107b420212a9f < a0f90c8815706981c483a652a6aefca51a5e191ca0f90c8815706981c483a652a6aefca51a5e191c
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.103-15.10.103-1
linuxlinux_kernel>= 0 < 5.16.7-15.16.7-1
linuxlinux_kernel>= 0 < 5.16.7-15.16.7-1
linuxlinux_kernel>= 0 < 5.16.7-15.16.7-1
linuxlinux_kernel>= 4.14 < 4.14.2644.14.264
linuxlinux_kernel>= 4.15 < 4.19.2274.19.227
linuxlinux_kernel>= 4.20 < 5.4.1755.4.175
linuxlinux_kernel>= 5.11 < 5.15.185.15.18
linuxlinux_kernel>= 5.16 < 5.16.45.16.4
linuxlinux_kernel>= 5.5 < 5.10.955.10.95

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
ghsa7.5HIGH
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.