Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2022-4696
Description:There exists a use-after-free vulnerability in the Linux kernel through io_uring and the IORING_OP_SPLICE operation. If IORING_OP_SPLICE is missing the IO_WQ_WORK_FILES flag, which signals that the operation won't use current->nsproxy, so its reference counter is not increased. This assumption is not always true as calling io_splice on specific files will call the get_uts function which will use current->nsproxy leading to invalidly decreasing its reference counter later causing the use-after-free vulnerability. We recommend upgrading to version 5.10.160 or above
Test IDs: 1.3.6.1.4.1.25623.1.0.705324   1.3.6.1.4.1.25623.1.0.893349  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2022-4696
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?h=linux-5.10.y&id=75454b4bbfc7e6a4dd8338556f36ea9107ddf61a
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?h=linux-5.10.y&id=75454b4bbfc7e6a4dd8338556f36ea9107ddf61a
https://kernel.dance/#75454b4bbfc7e6a4dd8338556f36ea9107ddf61a
https://kernel.dance/#75454b4bbfc7e6a4dd8338556f36ea9107ddf61a




© 1998-2025 E-Soft Inc. All rights reserved.