Use of uninitialized resource in Linux kernel - CVE-2022-2308
Published: November 30, 2022
Vulnerability details
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to usage of uninitialized resources in vDPA with VDUSE backend in Linux kernel. A local user can pass specially crafted data to the Virtio drivers, trigger uninitialized usage of resources and gain access to sensitive information.
Affected software
Slackware Linux
linux-5.15.80/kernel-generic
linux-5.15.80/kernel-huge
linux-5.15.80/kernel-modules
linux-5.15.80/kernel-headers
How to mitigate CVE-2022-2308
linux-5.15.80/kernel-huge - update to 5.15.80
linux-5.15.80/kernel-modules - update to 5.15.80
linux-5.15.80/kernel-headers - update to 5.15.80_smp