CVE-2022-0330: High severity Linux Linux kernel vulnerability
A random memory access flaw was found in the Linux kernel's GPU i915 kernel driver functionality in the way a user may run malicious code on the GPU. This flaw allows a local user to crash the system or escalate their privileges on the system.
Other sources
A random memory access flaw was found in the Linux kernel’s GPU i915 kernel driver functionality in the way a user may run malicious code on the GPU. This flaw allows a local user to crash the system or escalate their privileges on the system.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernel-rtto a version that resolves this vulnerability.Fixed in 0:3.10.0-1160.59.1.rt56.1200.el7 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:3.10.0-1160.59.1.el7 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:3.10.0-514.99.1.el7 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:3.10.0-693.99.1.el7 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:3.10.0-957.92.1.el7 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:3.10.0-1062.63.1.el7 - Upgrade
Upgrade
redhat/kernel-rtto a version that resolves this vulnerability.Fixed in 0:4.18.0-348.20.1.rt7.150.el8_5 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:4.18.0-348.20.1.el8_5 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:4.18.0-147.64.1.el8_1 - Upgrade
Upgrade
redhat/kernel-rtto a version that resolves this vulnerability.Fixed in 0:4.18.0-193.79.1.rt13.129.el8_2 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:4.18.0-193.79.1.el8_2 - Upgrade
Upgrade
redhat/kernel-rtto a version that resolves this vulnerability.Fixed in 0:4.18.0-305.40.1.rt7.112.el8_4 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:4.18.0-305.40.1.el8_4 - Upgrade
Upgrade
redhat/redhat-virtualization-hostto a version that resolves this vulnerability.Fixed in 0:4.3.22-20220330.1.el7_9 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 5.17
Event History
Parent advisories
This vulnerability appears in the following advisories.
- RHSA-2022:0622
- RHSA-2022:0592
- RHSA-2022:0620
- RHSA-2022:1106
- RHSA-2022:1104
- RHSA-2022:1107
- RHSA-2022:1103
- RHSA-2022:0712
- RHSA-2022:0718
- RHSA-2022:0819
- RHSA-2022:0825
- RHSA-2022:0849
- RHSA-2022:0823
- RHSA-2022:0851
- RHSA-2022:0958
- RHSA-2022:0821
- RHSA-2022:0820
- RHSA-2022:0925
- RHSA-2022:0771
- RHSA-2022:0772
- RHSA-2022:0777
- RHSA-2022:1263
- RHSA-2022:0841
Frequently Asked Questions
What is the severity of CVE-2022-0330?
CVE-2022-0330 is considered a high severity vulnerability that could allow local users to crash the system or escalate their privileges.
How do I fix CVE-2022-0330?
To fix CVE-2022-0330, upgrade to the patched versions of the affected Red Hat kernel packages listed in the advisory.
Which systems are affected by CVE-2022-0330?
CVE-2022-0330 affects multiple versions of the Linux kernel in Red Hat Enterprise Linux and its derivatives.
What type of vulnerability is CVE-2022-0330?
CVE-2022-0330 is a random memory access flaw within the GPU i915 kernel driver functionality.
Can CVE-2022-0330 lead to remote code execution?
No, CVE-2022-0330 is not directly associated with remote code execution but can result in system crashes or privilege escalation.