CVE-2022-3424
Summary
| CVE | CVE-2022-3424 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-03-06 23:15:00 UTC |
| Updated | 2023-11-07 03:51:00 UTC |
| Description | A use-after-free flaw was found in the Linux kernel’s SGI GRU driver in the way the first gru_file_unlocked_ioctl function is called by the user, where a fail pass occurs in the gru_check_chiplet_assignment function. This flaw allows a local user to crash or potentially escalate their privileges on the system. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Unicorn! · GitHub |
MISC |
github.com |
|
| [SECURITY] [DLA 3404-1] linux-5.10 security update |
MLIST |
lists.debian.org |
|
| 2132640 – (CVE-2022-3424) CVE-2022-3424 kernel: Use after Free in gru_set_context_option leading to kernel panic |
MISC |
bugzilla.redhat.com |
|
| CVE-2022-3424 Linux Kernel Vulnerabilities in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| [PATCH v4] misc: sgi-gru: fix use-after-free error in gru_set_context_option, gru_fault and gru_handle_user_call_os - Zheng Wang |
MISC |
lore.kernel.org |
|
| [SECURITY] [DLA 3403-1] linux security update |
MLIST |
lists.debian.org |
|
| [PATCH v4] misc: sgi-gru: fix use-after-free error in gru_set_context_option, gru_fault and gru_handle_user_call_os - Zheng Wang |
|
lore.kernel.org |
|
| [PATCH] misc: sgi-gru: fix use-after-free error in gru_set_context_option, gru_fault and gru_handle_user_call_os — Linux Kernel |
MISC |
www.spinics.net |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160767 Oracle Enterprise Linux Security Update for unbreakable enterprise kernel (ELSA-2023-12565)
- 181765 Debian Security Update for linux-5.10 (DLA 3404-1)
- 181768 Debian Security Update for linux (DLA 3403-1)
- 183455 Debian Security Update for linux (CVE-2022-3424)
- 199161 Ubuntu Security Notification for Linux kernel (OEM) Vulnerabilities (USN-5856-1)
- 199212 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-5917-1)
- 199218 Ubuntu Security Notification for Linux kernel (Azure) Vulnerabilities (USN-5927-1)
- 199224 Ubuntu Security Notification for Linux kernel (Raspberry Pi) Vulnerabilities (USN-5934-1)
- 199226 Ubuntu Security Notification for Linux kernel (GCP) Vulnerabilities (USN-5939-1)
- 199230 Ubuntu Security Notification for Linux kernel (Raspberry Pi) Vulnerabilities (USN-5940-1)
- 199239 Ubuntu Security Notification for Linux kernel (IBM) Vulnerabilities (USN-5951-1)
- 199260 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-5982-1)
- 199261 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-5984-1)
- 199265 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-5987-1)
- 199267 Ubuntu Security Notification for Linux kernel (GCP) Vulnerabilities (USN-5991-1)
- 199276 Ubuntu Security Notification for Linux kernel (BlueField) Vulnerabilities (USN-6000-1)
- 199280 Ubuntu Security Notification for Linux kernel (Intel IoTG) Vulnerabilities (USN-6004-1)
- 199294 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6024-1)
- 199300 Ubuntu Security Notification for Linux kernel (Qualcomm Snapdragon) Vulnerabilities (USN-6030-1)
- 199502 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-5975-1)
- 199541 Ubuntu Security Notification for Linux kernel (Azure) Vulnerabilities (USN-5924-1)
- 199570 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-5981-1)
- 199587 Ubuntu Security Notification for Linux kernel (GCP) Vulnerabilities (USN-6009-1)
- 379043 Alibaba Cloud Linux Security Update for cloud-kernel (ALINUX3-SA-2023:0136)
- 379435 Alibaba Cloud Linux Security Update for cloud-kernel (ALINUX2-SA-2024:0012)
- 390285 Oracle Managed Virtualization (VM) Server for x86 Security Update for kernel (OVMSA-2023-0017)
- 390286 Oracle Managed Virtualization (VM) Server for x86 Security Update for kernel (OVMSA-2023-0018)
- 672747 EulerOS Security Update for kernel (EulerOS-SA-2023-1469)
- 672914 EulerOS Security Update for kernel (EulerOS-SA-2023-1781)
- 672951 EulerOS Security Update for kernel (EulerOS-SA-2023-1759)
- 673117 EulerOS Security Update for kernel (EulerOS-SA-2023-2152)
- 752839 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:3929-1)
- 752880 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:4053-1)
- 752889 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:3897-1)
- 752911 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:3998-1)
- 752913 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:4072-1)
- 752944 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:4273-1)
- 752959 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:4272-1)
- 753038 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:4573-1)
- 753039 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:4574-1)
- 753051 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:4589-1)
- 753060 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:4615-1)
- 753063 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:4617-1)
- 753613 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 34 for SLE 15 SP1) (SUSE-SU-2023:0227-1)
- 753614 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 29 for SLE 15 SP2) (SUSE-SU-2023:0229-1)
- 753615 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 29 for SLE 15 SP1) (SUSE-SU-2023:0231-1)
- 753616 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 31 for SLE 15 SP2) (SUSE-SU-2023:0237-1)
- 753617 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 33 for SLE 15 SP1) (SUSE-SU-2023:0235-1)
- 753618 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 30 for SLE 15 SP1) (SUSE-SU-2023:0240-1)
- 753619 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 26 for SLE 15 SP2) (SUSE-SU-2023:0245-1)
- 753620 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 12 for SLE 15 SP3) (SUSE-SU-2023:0262-1)
- 753623 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 4 for SLE 15 SP4) (SUSE-SU-2023:0270-1)
- 753625 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 25 for SLE 15 SP3) (SUSE-SU-2023:0267-1)
- 753628 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 17 for SLE 15 SP3) (SUSE-SU-2023:0281-1)
- 753630 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 1 for SLE 15 SP4) (SUSE-SU-2023:0277-1)
- 753662 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 3 for SLE 15 SP4) (SUSE-SU-2023:0331-1)
- 753703 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:0416-1)
- 753707 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:0416-1)
- 753727 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:0416-1)