CVE-2022-3910: Major Security Vulnerability in the Linux Kernel!

Recently announced the vulnerability CVE-2022-3910 (CVSS score: 7.4) in the Linux kernel. This is a bug in updating the Reference Count in io_uring.

linuxkernel

io_uring is a system call interface for Linux. It first came in version 5.1 of the Linux kernel in 2019. It allows an application to initiate system calls that can be executed asynchronously.

In the Linux kernel, an incorrect reference count update to io_uring leads to Use-After-Free and local privilege escalation. When io_msg_ring is called with a constant , calls io_fput_file() which incorrectly decrements its reference count. The constants they are permanently registered and should not be operated separately.

Bug CVE-2022-3910 was fixed a few hours ago.

Currently, the kernel developers have released an official security update.

Users are advised to update the servers immediately and apply them for other distributions as they become available. It is also recommended that they only allow access to local systems to trusted users and always monitor their systems.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.082 registrants.
Linux kernel, Linux, kernel

Written by Anastasis Vasileiadis

Translations are like women. When they are beautiful they are not faithful and when they are faithful they are not beautiful.

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).