CVE-2022-40768
Summary
| CVE | CVE-2022-40768 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-09-18 05:15:00 UTC |
| Updated | 2023-11-07 03:52:00 UTC |
| Description | drivers/scsi/stex.c in the Linux kernel through 5.19.9 allows local users to obtain sensitive information from kernel memory because stex_queuecommand_lck lacks a memset for the PASSTHRU_CMD case. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 36 Update: kernel-5.19.15-201.fc36 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [PATCH] scsi: stex: properly zero out the passthrough command structure - Greg Kroah-Hartman |
MISC |
lore.kernel.org |
|
| oss-security - Re: Linux kernel: information disclosure in stex_queuecommand_lck |
MLIST |
www.openwall.com |
|
| [SECURITY] [DLA 3245-1] linux security update |
MLIST |
lists.debian.org |
|
| [SECURITY] Fedora 35 Update: kernel-5.19.15-101.fc35 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 37 Update: kernel-5.19.15-301.fc37 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 37 Update: kernel-5.19.15-301.fc37 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| oss-security - Linux kernel: information disclosure in stex_queuecommand_lck |
MISC |
www.openwall.com |
|
| [SECURITY] Fedora 36 Update: kernel-5.19.15-201.fc36 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| kernel/git/torvalds/linux.git - Linux kernel source tree |
MISC |
git.kernel.org |
|
| [PATCH] scsi: stex: properly zero out the passthrough command structure - Greg Kroah-Hartman |
|
lore.kernel.org |
|
| [SECURITY] Fedora 35 Update: kernel-5.19.15-101.fc35 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160345 Oracle Enterprise Linux Security Update for unbreakable enterprise kernel (ELSA-2022-10065)
- 160353 Oracle Enterprise Linux Security Update for unbreakable enterprise kernel (ELSA-2022-10072)
- 160355 Oracle Enterprise Linux Security Update for unbreakable enterprise kernel-container (ELSA-2022-10073)
- 181219 Debian Security Update for linux (CVE-2022-40768)
- 181565 Debian Security Update for linux (DLA 3245-1)
- 198999 Ubuntu Security Notification for Linux kernel (OEM) Vulnerabilities (USN-5693-1)
- 199029 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-5728-1)
- 199030 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-5727-1)
- 199031 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-5729-1)
- 199036 Ubuntu Security Notification for Linux kernel (GCP) Vulnerabilities (USN-5727-2)
- 199037 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-5728-2)
- 199038 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-5729-2)
- 199051 Ubuntu Security Notification for Linux kernel (GCP) Vulnerabilities (USN-5728-3)
- 199072 Ubuntu Security Notification for Linux kernel (Azure) Vulnerabilities (USN-5774-1)
- 283201 Fedora Security Update for kernel (FEDORA-2022-2cfbe17910)
- 283209 Fedora Security Update for kernel (FEDORA-2022-b948fc3cfb)
- 283477 Fedora Security Update for kernel (FEDORA-2022-1a5b125ac6)
- 354107 Amazon Linux Security Advisory for kernel : ALAS2KERNEL-5.4-2022-038
- 354110 Amazon Linux Security Advisory for kernel : ALAS2KERNEL-5.10-2022-022
- 354113 Amazon Linux Security Advisory for kernel : ALAS2KERNEL-5.15-2022-010
- 354114 Amazon Linux Security Advisory for kernel : ALAS2-2022-1876
- 354251 Amazon Linux Security Advisory for kernel : ALAS-2022-1645
- 377891 Alibaba Cloud Linux Security Update for cloud-kernel (ALINUX3-SA-2023:0002)
- 378468 Alibaba Cloud Linux Security Update for cloud-kernel (ALINUX3-SA-20230042)
- 378512 Alibaba Cloud Linux Security Update for cloud-kernel (ALINUX3-SA-2023:0042)
- 390269 Oracle VM Server for x86 Security Update for kernel (OVMSA-2022-0031)
- 6140029 AWS Bottlerocket Security Update for kernel (GHSA-jw9m-fq9g-prgw)
- 6140316 AWS Bottlerocket Security Update for kernel (GHSA-jw9m-fq9g-prgw)
- 672711 EulerOS Security Update for kernel (EulerOS-SA-2023-1507)
- 752724 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:3775-1)
- 752889 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:3897-1)
- 752911 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:3998-1)
- 752913 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:4072-1)
- 752944 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:4273-1)
- 752959 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:4272-1)
- 753038 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:4573-1)
- 753039 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:4574-1)
- 753051 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:4589-1)
- 753060 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:4615-1)
- 753063 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:4617-1)
- 753374 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:3809-1)
- 753703 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:0416-1)
- 753707 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:0416-1)
- 753727 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:0416-1)
- 904028 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (10978)
- 904032 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (10985)
- 904622 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (10985-1)
- 904725 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (10978-1)
- 905784 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (10985-2)
- 906307 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (10978-2)