UBUNTU-CVE-2022-2959
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-2959
UBUNTU-CVE-2022-2959
Summary:
Details: A race condition was found in the Linux kernel's watch queue due to a missing lock in pipe_resize_ring(). The specific flaw exists within the handling of pipe buffers. The issue results from the lack of proper locking when performing operations on an object. This flaw allows a local user to crash the system or escalate their privileges on the system.
References: https://ubuntu.com/security/CVE-2022-2959, https://www.zerodayinitiative.com/advisories/ZDI-CAN-17291/, https://git.kernel.org/linus/189b0ddc245139af81198d1a3637cac74f96e13a, https://ubuntu.com/security/notices/USN-5594-1, https://ubuntu.com/security/notices/USN-5599-1, https://ubuntu.com/security/notices/USN-5602-1, https://ubuntu.com/security/notices/USN-5616-1, https://ubuntu.com/security/notices/USN-5623-1, https://www.cve.org/CVERecord?id=CVE-2022-2959
Affected packages
Package
Name: linux-hwe-edge
Purl: pkg:deb/ubuntu/[email protected]~16.04.1?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
