UBUNTU-CVE-2022-33981
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-33981
UBUNTU-CVE-2022-33981
Summary:
Details: drivers/block/floppy.c in the Linux kernel before 5.17.6 is vulnerable to a denial of service, because of a concurrency use-after-free flaw after deallocating raw_cmd in the raw_cmd_ioctl function.
References: https://ubuntu.com/security/CVE-2022-33981, https://www.openwall.com/lists/oss-security/2022/04/28/1, https://git.kernel.org/linus/233087ca063686964a53c829d547c7571e3f67bf, https://github.com/torvalds/linux/commit/233087ca063686964a53c829d547c7571e3f67bf, https://seclists.org/oss-sec/2022/q2/66, https://exchange.xforce.ibmcloud.com/vulnerabilities/225362, https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.17.6, https://ubuntu.com/security/notices/USN-5514-1, https://ubuntu.com/security/notices/USN-5518-1, https://ubuntu.com/security/notices/USN-5539-1, https://ubuntu.com/security/notices/USN-5560-1, https://ubuntu.com/security/notices/USN-5560-2, https://ubuntu.com/security/notices/USN-5564-1, https://www.cve.org/CVERecord?id=CVE-2022-33981
Affected packages
Package
Name: linux-azure
Purl: pkg:deb/ubuntu/linux-azure?arch=source&distro=trusty%2Fesm
Affected ranges
Type: ECOSYSTEM
Events:
