SB2023041921 - Privilege escalation in Linux kernel DVB driver
Published: April 19, 2023
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 4 secuirty vulnerabilities.
1) Use-after-free (CVE-ID: CVE-2022-45884)
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a use-after-free error in drivers/media/dvb-core/dvbdev.c in Linux kernel related to dvb_register_device() function dynamically allocating fops. A local user can trigger a use-after-free error and execute arbitrary code with elevated privileges.
2) Use-after-free (CVE-ID: CVE-2022-45919)
The vulnerability allows a local user to escalate privileges on the system.
3) Use-after-free (CVE-ID: CVE-2022-45885)
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a use-after-free error in drivers/media/dvb-core/dvb_frontend.c in Linux kernel. A local user can trigger a race condition and execute arbitrary code with elevated privileges.
4) Use-after-free (CVE-ID: CVE-2022-45886)
The vulnerability allows a local user to escalate privileges on the system.
Remediation
Install update from vendor's website.
References
- https://lore.kernel.org/linux-media/20221115131822.6640-4-imv4bel@gmail.com/
- https://lore.kernel.org/linux-media/20221115131822.6640-1-imv4bel@gmail.com/
- https://security.netapp.com/advisory/ntap-20230113-0006/
- https://lore.kernel.org/linux-media/20221121063308.GA33821@ubuntu/T/#u
- https://security.netapp.com/advisory/ntap-20230113-0008/
- https://lore.kernel.org/linux-media/20221115131822.6640-2-imv4bel@gmail.com/
- https://lore.kernel.org/linux-media/20221115131822.6640-3-imv4bel@gmail.com/