Risk | Low |
Patch available | YES |
Number of vulnerabilities | 1 |
CVE-ID | CVE-2022-2308 |
CWE-ID | CWE-908 |
Exploitation vector | Local |
Public exploit | N/A |
Vulnerable software Subscribe |
Linux kernel Operating systems & Components / Operating system |
Vendor | Linux Foundation |
This security bulletin contains one low risk vulnerability.
EUVDB-ID: #VU69765
Risk: Low
CVSSv3.1:
CVE-ID: CVE-2022-2308
CWE-ID:
CWE-908 - Use of Uninitialized Resource
Exploit availability: No
DescriptionThe vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to usage of uninitialized resources in vDPA with VDUSE backend in Linux kernel. A local user can pass specially crafted data to the Virtio drivers, trigger uninitialized usage of resources and gain access to sensitive information.
Install updates from vendor's website.
Vulnerable software versionsLinux kernel: All versions
http://bugzilla.redhat.com/show_bug.cgi?id=2103900
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?