CVE-2022-4696
Summary
| CVE | CVE-2022-4696 |
|---|---|
| State | PUBLISHED |
| Assigner | |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-01-11 13:15:09 UTC |
| Updated | 2026-09-01 18:05:07 UTC |
| Description | There exists a use-after-free vulnerability in the Linux kernel through io_uring and the IORING_OP_SPLICE operation. If IORING_OP_SPLICE is missing the IO_WQ_WORK_FILES flag, which signals that the operation won't use current->nsproxy, so its reference counter is not increased. This assumption is not always true as calling io_splice on specific files will call the get_uts function which will use current->nsproxy leading to invalidly decreasing its reference counter later causing the use-after-free vulnerability. We recommend upgrading to version 5.10.160 or above |
Risk And Classification
Primary CVSS: v3.1 7.8 HIGH from [email protected]
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Problem Types: CWE-763 | CWE-416 | CWE-763 CWE-763 Release of Invalid Pointer or Reference
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | [email protected] | Secondary | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | CNA | CVSS | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Linux | Linux Kernel | All | All | All | All |
| Hardware | Netapp | H300s | - | All | All | All |
| Operating System | Netapp | H300s Firmware | - | All | All | All |
| Hardware | Netapp | H410c | - | All | All | All |
| Operating System | Netapp | H410c Firmware | - | All | All | All |
| Hardware | Netapp | H410s | - | All | All | All |
| Operating System | Netapp | H410s Firmware | - | All | All | All |
| Hardware | Netapp | H500s | - | All | All | All |
| Operating System | Netapp | H500s Firmware | - | All | All | All |
| Hardware | Netapp | H700s | - | All | All | All |
| Operating System | Netapp | H700s Firmware | - | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux Kernel | affected 5.7-rc1 5.10.159 custom | Not specified |
| ADP | Linux | Linux Kernel | affected 5.7-rc1 5.10.159 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| kernel/git/stable/linux.git - Linux kernel stable tree | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | Mailing List, Patch, Vendor Advisory |
| ???????? | af854a3a-2127-422b-91ae-364da2661108 | kernel.dance | Exploit, Third Party Advisory |
| security.netapp.com/advisory/ntap-20230223-0003 | af854a3a-2127-422b-91ae-364da2661108 | security.netapp.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Bing-Jhong Billy Jheng of Starlabs (en)
Legacy QID Mappings
- 181491 Debian Security Update for linux (DSA 5324-1)
- 181618 Debian Security Update for linux-5.10 (DLA 3349-1)
- 184717 Debian Security Update for linux (CVE-2022-4696)
- 377963 Alibaba Cloud Linux Security Update for cloud-kernel (ALINUX3-SA-2023:0017)
- 378468 Alibaba Cloud Linux Security Update for cloud-kernel (ALINUX3-SA-20230042)
- 378512 Alibaba Cloud Linux Security Update for cloud-kernel (ALINUX3-SA-2023:0042)
- 610480 Google Android Devices April 2023 Security Patch Missing
- 610485 Google Android May 2023 Security Patch Missing for Samsung
- 672914 EulerOS Security Update for kernel (EulerOS-SA-2023-1781)
- 672951 EulerOS Security Update for kernel (EulerOS-SA-2023-1759)
- 906970 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (26650-1)