UBUNTU-CVE-2022-47929
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-47929
UBUNTU-CVE-2022-47929
Summary:
Details: In the Linux kernel before 6.1.6, a NULL pointer dereference bug in the traffic control subsystem allows an unprivileged user to trigger a denial of service (system crash) via a crafted traffic control configuration that is set up with "tc qdisc" and "tc class" commands. This affects qdisc_graft in net/sched/sch_api.c.
References: https://ubuntu.com/security/CVE-2022-47929, https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=96398560f26aa07e8f2969d73c8197e6a6d10407, https://tldp.org/HOWTO/Traffic-Control-HOWTO/components.html, https://www.spinics.net/lists/netdev/msg555705.html, https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.6, https://ubuntu.com/security/notices/USN-5915-1, https://ubuntu.com/security/notices/USN-5917-1, https://ubuntu.com/security/notices/USN-5924-1, https://ubuntu.com/security/notices/USN-5927-1, https://ubuntu.com/security/notices/USN-5934-1, https://ubuntu.com/security/notices/USN-5939-1, https://ubuntu.com/security/notices/USN-5940-1, https://ubuntu.com/security/notices/USN-5951-1, https://ubuntu.com/security/notices/USN-5975-1, https://ubuntu.com/security/notices/USN-5981-1, https://ubuntu.com/security/notices/USN-5984-1, https://ubuntu.com/security/notices/USN-5991-1, https://ubuntu.com/security/notices/USN-6000-1, https://ubuntu.com/security/notices/USN-6001-1, https://ubuntu.com/security/notices/USN-6009-1, https://ubuntu.com/security/notices/USN-6013-1, https://ubuntu.com/security/notices/USN-6014-1, https://ubuntu.com/security/notices/USN-6024-1, https://ubuntu.com/security/notices/USN-6025-1, https://ubuntu.com/security/notices/USN-6030-1, https://ubuntu.com/security/notices/USN-6040-1, https://ubuntu.com/security/notices/USN-6057-1, https://ubuntu.com/security/notices/USN-6134-1, https://ubuntu.com/security/notices/USN-6247-1, https://ubuntu.com/security/notices/USN-6248-1, https://www.cve.org/CVERecord?id=CVE-2022-47929
Affected packages
Package
Name: linux-aws
Purl: pkg:deb/ubuntu/linux-aws?arch=source&distro=trusty%2Fesm
Affected ranges
Type: ECOSYSTEM
Events:
