Wind River Support Network

HomeDefectsLIN1021-4017
Fixed

LIN1021-4017 : Security Advisory - linux - CVE-2022-2327

Created: Jul 24, 2022    Updated: Jul 31, 2022
Resolved Date: Jul 26, 2022
Found In Version: 10.21.20.1
Fix Version: 10.21.20.14
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Kernel

Description

io_uring use work_flags to determine which identity need to grab from the calling process to make sure it is consistent with the calling process when executing IORING_OP. Some operations are missing some types, which can lead to incorrect reference counts which can then lead to a double free. We recommend upgrading the kernel past commit df3f3bb5059d20ef094d6b2f0256c4bf4127a859

CREATE(Triage):(User=admin) CVE-2022-2327 (https://nvd.nist.gov/vuln/detail/CVE-2022-2327)

CVEs


Live chat
Online