VDB
BDU%3A2022-05916
BDU%3A2022-05916
PUBLISHED
CVSS 9.300000190734863 CRITICAL
Уязвимость компонента drivers/infiniband/core/ucma.c ядра операционной системы Linux, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
Risk Scores
CVSS 2.0
9.300000190734863
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| ООО «РусБИТех-Астра», Сообщество свободного программного обеспечения | Astra Linux Special Edition (запись в едином реестре российских программ №369), Debian GNU/Linux, Linux |
Timeline
- Sep 26, 2022 CVE Published
- Jun 10, 2024 CVE Updated
- Mar 19, 2026 Distribution Patch
- Mar 19, 2026 Distribution Patch
- Mar 19, 2026 Distribution Patch
- Mar 19, 2026 Distribution Patch
References
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10 url
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-36385 url
- https://nvd.nist.gov/vuln/detail/CVE-2020-36385 url
- https://security.netapp.com/advisory/ntap-20210720-0004/ url
- https://security-tracker.debian.org/tracker/CVE-2020-36385 url
- https://sites.google.com/view/syzscope/kasan-use-after-free-read-in-ucma_close-2 url
- https://syzkaller.appspot.com/bug?id=457491c4672d7b52c1007db213d93e47c711fae6 url
- https://ubuntu.com/security/notices/USN-5136-1 url
- https://ubuntu.com/security/notices/USN-5137-1 url
- https://ubuntu.com/security/notices/USN-5137-2 url
- https://ubuntu.com/security/notices/USN-5343-1 url
- https://wiki.astralinux.ru/astra-linux-se16-bulletin-20220829SE16 url
- https://www.cve.org/CVERecord?id=CVE-2020-36385 url
- https://www.starwindsoftware.com/security/sw-20220802-0002/ url
- https://git.kernel.org/linus/f5449e74802c1112dea984aec8af7a33c4516af1 advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=f5449e74802c1112dea984aec8af7a33c4516af1 advisory
- https://wiki.astralinux.ru/astra-linux-se47-bulletin-2022-0926SE47 advisory