CVE-2022-2959
Summary
| CVE | CVE-2022-2959 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-08-25 18:15:00 UTC |
| Updated | 2023-05-26 19:42:00 UTC |
| Description | A race condition was found in the Linux kernel's watch queue due to a missing lock in pipe_resize_ring(). The specific flaw exists within the handling of pipe buffers. The issue results from the lack of proper locking when performing operations on an object. This flaw allows a local user to crash the system or escalate their privileges on the system. |
Risk And Classification
Problem Types: CWE-362 | CWE-667
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Linux | Linux Kernel | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| August 2022 Linux Kernel 5.18 Vulnerabilities in NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | |
| pipe: Fix missing lock in pipe_resize_ring() · torvalds/linux@189b0dd · GitHub | MISC | github.com | |
| ZDI-22-1165 | Zero Day Initiative | MISC | www.zerodayinitiative.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160423 Oracle Enterprise Linux Security Update for kernel (ELSA-2023-0334)
- 180959 Debian Security Update for linux (CVE-2022-2959)
- 198921 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-5594-1)
- 198927 Ubuntu Security Notification for Linux kernel (Oracle) Vulnerabilities (USN-5599-1)
- 198929 Ubuntu Security Notification for Linux kernel (Raspberry Pi) Vulnerabilities (USN-5602-1)
- 198942 Ubuntu Security Notification for Linux kernel (Intel IoTG) Vulnerabilities (USN-5616-1)
- 198950 Ubuntu Security Notification for Linux kernel (HWE) Vulnerabilities (USN-5623-1)
- 241008 Red Hat Update for kernel (RHSA-2022:8973)
- 241009 Red Hat Update for kernel-rt (RHSA-2022:8974)
- 241022 Red Hat Update for kpatch-patch (RHSA-2022:9082)
- 241095 Red Hat Update for kernel (RHSA-2023:0334)
- 241096 Red Hat Update for kernel-rt (RHSA-2023:0300)
- 241101 Red Hat Update for kpatch-patch (RHSA-2023:0348)
- 377117 Alibaba Cloud Linux Security Update for cloud-kernel (ALINUX3-SA-2022:0158)
- 610462 Google Android Devices January 2023 Security Patch Missing
- 610467 Google Android February 2023 Security Patch Missing for Samsung
- 752594 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:3293-1)
- 752930 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 0 for SLE 15 SP4) (SUSE-SU-2022:4113-1)
- 753063 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:4617-1)
- 753167 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:3288-1)
- 903788 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (10705) (DEPRECATED)
- 903858 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (10692)
- 904014 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (10705-1)
- 904139 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (10692-1)
- 906071 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (10705-2)
- 906274 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (10692-2)
- 940904 AlmaLinux Security Update for kernel (ALSA-2023:0334)
- 940910 AlmaLinux Security Update for kernel-rt (ALSA-2023:0300)
- 960503 Rocky Linux Security Update for kernel-rt (RLSA-2023:0300)
- 960587 Rocky Linux Security Update for kernel (RLSA-2023:0334)