UBUNTU-CVE-2022-3176
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-3176
UBUNTU-CVE-2022-3176
Summary:
Details: There exists a use-after-free in io_uring in the Linux kernel. Signalfd_poll() and binder_poll() use a waitqueue whose lifetime is the current task. It will send a POLLFREE notification to all waiters before the queue is freed. Unfortunately, the io_uring poll doesn't handle POLLFREE. This allows a use-after-free to occur if a signalfd or binder fd is polled with io_uring poll, and the waitqueue gets freed. We recommend upgrading past commit fc78b2fc21f10c4c9c4d5d659a685710ffa63659
References: https://ubuntu.com/security/CVE-2022-3176, https://kernel.dance/#fc78b2fc21f10c4c9c4d5d659a685710ffa63659, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit?h=linux-5.4.y&id=fc78b2fc21f10c4c9c4d5d659a685710ffa63659, https://ubuntu.com/security/notices/USN-5667-1, https://ubuntu.com/security/notices/USN-5668-1, https://ubuntu.com/security/notices/USN-5677-1, https://ubuntu.com/security/notices/USN-5682-1, https://ubuntu.com/security/notices/USN-5683-1, https://ubuntu.com/security/notices/USN-5703-1, https://ubuntu.com/security/notices/USN-5706-1, https://www.cve.org/CVERecord?id=CVE-2022-3176
Affected packages
Package
Name: linux-hwe-edge
Purl: pkg:deb/ubuntu/linux-hwe-edge?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
