A race condition was found the Linux kernel in perf_event_open() which can be exploited by an unprivileged user to gain root privileges. The bug allows to build several exploit primitives such as kernel address information leak, arbitrary execution, etc.
References
| Link | Resource |
|---|---|
| https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=3ac6487e584a1eb54071dbe1212e05b884136704 | Mailing List Patch Vendor Advisory |
| https://security.netapp.com/advisory/ntap-20230214-0006/ | Patch Third Party Advisory |
| https://www.openwall.com/lists/oss-security/2022/05/20/2 | Mailing List Patch Third Party Advisory |
| https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=3ac6487e584a1eb54071dbe1212e05b884136704 | Mailing List Patch Vendor Advisory |
| https://security.netapp.com/advisory/ntap-20230214-0006/ | Patch Third Party Advisory |
| https://www.openwall.com/lists/oss-security/2022/05/20/2 | Mailing List Patch Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
21 Nov 2024, 06:41
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=3ac6487e584a1eb54071dbe1212e05b884136704 - Mailing List, Patch, Vendor Advisory | |
| References | () https://security.netapp.com/advisory/ntap-20230214-0006/ - Patch, Third Party Advisory | |
| References | () https://www.openwall.com/lists/oss-security/2022/05/20/2 - Mailing List, Patch, Third Party Advisory |
04 Aug 2023, 17:41
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
|
| CPE | cpe:2.3:a:netapp:hci_baseboard_management_controller:h700s:*:*:*:*:*:*:* cpe:2.3:a:netapp:hci_baseboard_management_controller:h500s:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* cpe:2.3:a:netapp:hci_baseboard_management_controller:h300s:*:*:*:*:*:*:* cpe:2.3:a:netapp:hci_baseboard_management_controller:h410s:*:*:*:*:*:*:* |
07 Sep 2022, 13:35
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.0 |
| CWE | CWE-362 | |
| CPE | cpe:2.3:o:linux:linux_kernel:5.18:rc9:*:*:*:*:*:* | |
| References | (MISC) https://www.openwall.com/lists/oss-security/2022/05/20/2 - Mailing List, Patch, Third Party Advisory | |
| References | (MISC) https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=3ac6487e584a1eb54071dbe1212e05b884136704 - Mailing List, Patch, Vendor Advisory |
02 Sep 2022, 12:56
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2022-09-01 21:15
Updated : 2024-11-21 06:41
NVD link : CVE-2022-1729
Mitre link : CVE-2022-1729
CVE.ORG link : CVE-2022-1729
JSON object : View
Products Affected
netapp
- hci_baseboard_management_controller
linux
- linux_kernel
