CVE-2022-0617
Severity CVSS v4.0:
Pending analysis
Type:
CWE-476
NULL Pointer Dereference
Publication date:
16/02/2022
Last modified:
07/11/2023
Description
A flaw null pointer dereference in the Linux kernel UDF file system functionality was found in the way user triggers udf_file_write_iter function for the malicious UDF image. A local user could use this flaw to crash the system. Actual from Linux kernel 4.2-rc1 till 5.17-rc2.
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Base Score 2.0
4.90
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 4.2.1 (including) | 5.17 (excluding) |
| cpe:2.3:o:linux:linux_kernel:4.2:rc1:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:4.2:rc2:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:4.2:rc3:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:4.2:rc4:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:4.2:rc5:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:4.2:rc6:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:4.2:rc7:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:4.2:rc8:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:4.2.0:*:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:5.17:-:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:5.17:rc1:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:5.17:rc2:*:*:*:*:*:* | ||
| cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
| cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://www.openwall.com/lists/oss-security/2022/04/13/2
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=7fc3b7c2981bbd1047916ade327beccb90994eee
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=ea8569194b43f0f01f0a84c689388542c7254a1f
- https://lists.debian.org/debian-lts-announce/2022/03/msg00011.html
- https://lists.debian.org/debian-lts-announce/2022/03/msg00012.html
- https://lore.kernel.org/lkml/20220114172329.ygzry5rlz64ua2nr%40quack3.lan/T/
- https://www.debian.org/security/2022/dsa-5095
- https://www.debian.org/security/2022/dsa-5096



