Description
A use-after-free flaw was found in the Linux kernel’s FUSE filesystem in the way a user triggers write(). This flaw allows a local user to gain unauthorized access to data from the FUSE filesystem, resulting in privilege escalation.
CVSS breakdown
CVSS 3.1
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected products
- debian / debian_linux10.0 – 10.0
- debian / debian_linux9.0 – 9.0
- fedoraproject / fedora34 – 34
- fedoraproject / fedora35 – 35
- Linux / Linux kernel5.17 – 5.17
- Linux / Linux kernel5.17 – 5.17
- Linux / Linux kernel5.17 – 5.17
- Linux / Linux kernel5.17 – 5.17
- Linux / Linux kernel5.17 – 5.17
- Linux / Linux kernel2.6.35 – 4.9.320
- Linux / Linux kernel5.17 – 5.17
- Linux / Linux kernel5.17 – 5.17
- Linux / Linux kernel5.17 – 5.17
- NETAPP / h300e_firmware
- NETAPP / h300s_firmware
- NETAPP / h410c_firmware
- NETAPP / h410s_firmware
- NETAPP / h500e_firmware
- NETAPP / h500s_firmware
- NETAPP / h700e_firmware
- NETAPP / h700s_firmware
- oracle / communications_cloud_native_core_binding_support_function22.1.3 – 22.1.3
- RedHat / build_of_quarkus2.0 – 2.0
- RedHat / codeready_linux_builder
- RedHat / developer_tools1.0 – 1.0
- RedHat / enterprise_linux7.0 – 7.0
- RedHat / enterprise_linux6.0 – 6.0
- RedHat / enterprise_linux8.0 – 8.0
- RedHat / enterprise_linux_eus8.6 – 8.6
- RedHat / enterprise_linux_for_ibm_z_systems8.0 – 8.0
- RedHat / enterprise_linux_for_ibm_z_systems_eus8.6 – 8.6
- RedHat / enterprise_linux_for_power_little_endian8.0 – 8.0
- RedHat / enterprise_linux_for_power_little_endian_eus8.6 – 8.6
- RedHat / enterprise_linux_for_real_time8 – 8
- RedHat / enterprise_linux_for_real_time_for_nfv8 – 8
- RedHat / enterprise_linux_for_real_time_for_nfv_tus8.6 – 8.6
- RedHat / enterprise_linux_for_real_time_tus8.6 – 8.6
- RedHat / enterprise_linux_server_aus8.6 – 8.6
- RedHat / enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions8.6 – 8.6
- RedHat / enterprise_linux_server_tus8.6 – 8.6
- RedHat / enterprise_linux_server_update_services_for_sap_solutions8.6 – 8.6
- RedHat / virtualization_host4.0 – 4.0
References
- MISChttps://git.kernel.org/pub/scm/linux/kernel/git/mszeredi/fuse.git/commit/?h=for-next
- MISChttps://bugzilla.redhat.com/show_bug.cgi?id=2064855
- MAILING_LISThttps://lists.debian.org/debian-lts-announce/2022/07/msg00000.html
- VENDOR_ADVISORYhttps://www.debian.org/security/2022/dsa-5173
- VENDOR_ADVISORYhttps://www.oracle.com/security-alerts/cpujul2022.html
Updated 4m ago · 8 sources