VDB
BDU%3A2023-00744
BDU%3A2023-00744
PUBLISHED
CVSS 6.800000190734863 MEDIUM
Уязвимость функции io_statx() в модуле fs/io_uring.c компонента io_uring ядра операционной системы Linux, позволяющая нарушителю вызвать отказ в обслуживании или повысить привилегии
Risk Scores
CVSS 2.0
6.800000190734863
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Google Inc, Сообщество свободного программного обеспечения | Android, Linux |
Timeline
- Feb 15, 2023 CVE Published
- May 16, 2024 CVE Updated
References
- https://android.googlesource.com/kernel/common/+/bc80ea8a4296c4d75f7e3e27b65718cae09f20f1 url
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-20568 url
- https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/fs/io_uring.c?h=linux-5.10.y&id=3c48558be571e01f67e65edcf03193484eeb2b79 url
- https://kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.118 url
- https://lore.kernel.org/io-uring/YoOJ%2FT4QRKC+fAZE@google.com url
- https://lore.kernel.org/io-uring/YoOJ%2FT4QRKC+fAZE@google.com/ url
- https://source.android.com/docs/security/bulletin/pixel/2022-12-01 url
- https://www.cve.org/CVERecord?id=CVE-2022-20568 url
- https://source.android.com/security/bulletin/pixel/2022-12-01 advisory