CVE-2022-3586
Summary
| CVE | CVE-2022-3586 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-10-19 18:15:00 UTC |
| Updated | 2022-11-04 19:14:00 UTC |
| Description | A flaw was found in the Linux kernel’s networking code. A use-after-free was found in the way the sch_sfb enqueue function used the socket buffer (SKB) cb field after the same SKB had been enqueued (and freed) into a child qdisc. This flaw allows a local, unprivileged user to crash the system, causing a denial of service. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| sch_sfb: Don't assume the skb is still around after enqueueing to child · torvalds/linux@9efd232 · GitHub |
MISC |
github.com |
|
| Upcoming | Zero Day Initiative |
MISC |
www.zerodayinitiative.com |
|
| [SECURITY] [DLA 3173-1] linux-5.10 security update |
MLIST |
lists.debian.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160367 Oracle Enterprise Linux Security Update for unbreakable enterprise kernel (ELSA-2022-10108)
- 181147 Debian Security Update for linux (CVE-2022-3586)
- 181190 Debian Security Update for linux-5.10 (DLA 3173-1)
- 199087 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-5792-1)
- 199088 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-5791-1)
- 199089 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-5793-1)
- 199090 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-5790-1)
- 199091 Ubuntu Security Notification for Linux kernel (Azure) Vulnerabilities (USN-5791-2)
- 199094 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-5792-2)
- 199096 Ubuntu Security Notification for Linux kernel (Azure) Vulnerabilities (USN-5793-2)
- 199098 Ubuntu Security Notification for Linux kernel (IBM) Vulnerabilities (USN-5793-4)
- 199099 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-5793-3)
- 199100 Ubuntu Security Notification for Linux kernel (Azure) Vulnerabilities (USN-5791-3)
- 199119 Ubuntu Security Notification for Linux kernel (BlueField) Vulnerabilities (USN-5815-1)
- 199179 Ubuntu Security Notification for Linux kernel (GKE) Vulnerabilities (USN-5877-1)
- 199334 Ubuntu Security Notification for Linux kernel (OEM) Vulnerabilities (USN-6071-1)
- 199380 Ubuntu Security Notification for Linux kernel (OEM) Vulnerabilities (USN-6124-1)
- 199572 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-6045-1)
- 377891 Alibaba Cloud Linux Security Update for cloud-kernel (ALINUX3-SA-2023:0002)
- 378043 Alibaba Cloud Linux Security Update for cloud-kernel (ALINUX2-SA-2023:0011)
- 378468 Alibaba Cloud Linux Security Update for cloud-kernel (ALINUX3-SA-20230042)
- 378512 Alibaba Cloud Linux Security Update for cloud-kernel (ALINUX3-SA-2023:0042)
- 390272 Oracle Managed Virtualization (VM) Server for x86 Security Update for kernel (OVMSA-2023-0001)
- 672410 EulerOS Security Update for kernel (EulerOS-SA-2022-2796)
- 672495 EulerOS Security Update for kernel (EulerOS-SA-2023-1012)
- 672516 EulerOS Security Update for kernel (EulerOS-SA-2023-1037)
- 672532 EulerOS Security Update for kernel (EulerOS-SA-2023-1126)
- 672564 EulerOS Security Update for kernel (EulerOS-SA-2023-1102)
- 672653 EulerOS Security Update for kernel (EulerOS-SA-2023-1388)
- 672668 EulerOS Security Update for kernel (EulerOS-SA-2023-1360)
- 672711 EulerOS Security Update for kernel (EulerOS-SA-2023-1507)
- 752813 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:3930-1)
- 752839 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:3929-1)
- 752880 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:4053-1)
- 752889 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:3897-1)
- 752911 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:3998-1)
- 752913 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:4072-1)
- 752944 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:4273-1)
- 752959 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:4272-1)
- 753015 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 23 for SLE 15 SP3) (SUSE-SU-2022:4544-1)
- 753016 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 24 for SLE 15 SP2) (SUSE-SU-2022:4587-1)
- 753017 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 4 for SLE 15 SP4) (SUSE-SU-2022:4560-1)
- 753018 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 31 for SLE 15) (SUSE-SU-2022:4577-1)
- 753021 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 14 for SLE 15 SP3) (SUSE-SU-2022:4528-1)
- 753022 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 20 for SLE 15 SP3) (SUSE-SU-2022:4551-1)
- 753025 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 32 for SLE 15 SP1) (SUSE-SU-2022:4506-1)
- 753026 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 33 for SLE 15 SP1) (SUSE-SU-2022:4533-1)
- 753029 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 25 for SLE 15 SP3) (SUSE-SU-2022:4517-1)
- 753031 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 31 for SLE 15 SP2) (SUSE-SU-2022:4515-1)
- 753032 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 27 for SLE 15 SP2) (SUSE-SU-2022:4513-1)
- 753033 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 1 for SLE 15 SP4) (SUSE-SU-2022:4518-1)
- 753035 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 30 for SLE 15 SP2) (SUSE-SU-2022:4534-1)
- 753036 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 26 for SLE 15) (SUSE-SU-2022:4550-1)
- 753037 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 26 for SLE 15 SP2) (SUSE-SU-2022:4580-1)
- 753038 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:4573-1)
- 753039 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:4574-1)
- 753040 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 12 for SLE 15 SP3) (SUSE-SU-2022:4562-1)
- 753041 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 24 for SLE 15 SP3) (SUSE-SU-2022:4516-1)
- 753042 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 35 for SLE 15 SP1) (SUSE-SU-2022:4539-1)
- 753044 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 3 for SLE 15 SP4) (SUSE-SU-2022:4559-1)
- 753046 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 30 for SLE 15 SP1) (SUSE-SU-2022:4527-1)
- 753048 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 18 for SLE 15 SP3) (SUSE-SU-2022:4569-1)
- 753049 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 26 for SLE 12 SP5) (SUSE-SU-2022:4520-1)
- 753050 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 22 for SLE 15 SP3) (SUSE-SU-2022:4543-1)
- 753051 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:4589-1)
- 753060 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:4615-1)
- 753063 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:4617-1)
- 753703 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:0416-1)
- 753707 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:0416-1)
- 753727 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:0416-1)
- 904317 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (11298)
- 904332 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (11282)
- 904545 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (11298-1)
- 904710 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (11282-1)
- 905751 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (11298-2)
- 906247 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (11282-2)