UBUNTU-CVE-2022-21546
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-21546
UBUNTU-CVE-2022-21546
Summary:
Details: In the Linux kernel, the following vulnerability has been resolved: scsi: target: Fix WRITE_SAME No Data Buffer crash In newer version of the SBC specs, we have a NDOB bit that indicates there is no data buffer that gets written out. If this bit is set using commands like "sg_write_same --ndob" we will crash in target_core_iblock/file's execute_write_same handlers when we go to access the se_cmd->t_data_sg because its NULL. This patch adds a check for the NDOB bit in the common WRITE SAME code because we don't support it. And, it adds a check for zero SG elements in each handler in case the initiator tries to send a normal WRITE SAME with no data buffer.
References: https://ubuntu.com/security/CVE-2022-21546, https://www.cve.org/CVERecord?id=CVE-2022-21546, https://git.kernel.org/linus/ccd3f449052449a917a3e577d8ba0368f43b8f29, https://git.kernel.org/linus/ccd3f449052449a917a3e577d8ba0368f43b8f29, https://linux.oracle.com/cve/CVE-2022-21546.html, https://lore.kernel.org/all/[email protected]/, https://ubuntu.com/security/notices/USN-7654-1, https://ubuntu.com/security/notices/USN-7654-2, https://ubuntu.com/security/notices/USN-7654-3, https://ubuntu.com/security/notices/USN-7655-1, https://ubuntu.com/security/notices/USN-7654-4, https://ubuntu.com/security/notices/USN-7654-5, https://ubuntu.com/security/notices/USN-7686-1, https://ubuntu.com/security/notices/USN-7711-1, https://ubuntu.com/security/notices/USN-7712-1, https://ubuntu.com/security/notices/USN-7712-2
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/linux?arch=source&distro=esm-infra-legacy%2Ftrusty
Affected ranges
Type: ECOSYSTEM
Events:
