CVE-2022-0854: Infoleak
A flaw was found in the Linux kernel. Information leak may occur through swiotlb.
Other sources
A memory leak flaw was found in the Linux kernel’s DMA subsystem, in the way a user calls DMAFROMDEVICE. This flaw allows a local user to read random memory from the kernel space.
Affected Software
Remediation
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2022-0854?
CVE-2022-0854 is a memory leak flaw in the Linux kernel's DMA subsystem that allows a local user to read random memory from the kernel space.
How does CVE-2022-0854 affect Ubuntu?
Ubuntu is affected by CVE-2022-0854 if the Linux kernel version is between 5.14.0-1033.36 (inclusive) and 5.14.0-1034.36 (exclusive) on the focal release.
How does CVE-2022-0854 affect Red Hat?
Red Hat is affected by CVE-2022-0854 if the Linux kernel version is between 5.17 (inclusive) and 5.18 (exclusive).
How does CVE-2022-0854 affect Red Hat Kernel RT?
Red Hat Kernel RT is affected by CVE-2022-0854 if the kernel-rt version is 4.18.0-425.3.1.rt7.213.el8 on the el8 release, or if the kernel-rt version is 5.14.0-162.6.1.rt21.168.el9_1 on the el9_1 release.
How does CVE-2022-0854 affect Debian?
Debian is affected by CVE-2022-0854 if the Linux kernel version is one of the following: 4.19.249-2, 4.19.289-2, 5.10.178-3, 5.10.191-1, 6.1.38-1, 6.1.52-1, and 6.5.3-1.
What is the severity rating of CVE-2022-0854?
CVE-2022-0854 has a severity rating of 5.5 (medium).
What is the Common Weakness Enumeration (CWE) ID for CVE-2022-0854?
The Common Weakness Enumeration (CWE) ID for CVE-2022-0854 is CWE-401.
How can I fix CVE-2022-0854 on Ubuntu?
To fix CVE-2022-0854 on Ubuntu, update the linux-oem-5.14 package to version 5.14.0-1034.36 or later.
How can I fix CVE-2022-0854 on Red Hat?
To fix CVE-2022-0854 on Red Hat, update the Linux kernel to version 5.18 or later.
How can I fix CVE-2022-0854 on Red Hat Kernel RT?
To fix CVE-2022-0854 on Red Hat Kernel RT, update the kernel-rt package to version 4.18.0-425.3.1.rt7.213.el8 or 5.14.0-162.6.1.rt21.168.el9_1 or later.
How can I fix CVE-2022-0854 on Debian?
To fix CVE-2022-0854 on Debian, update the linux package to version 4.19.249-2, 4.19.289-2, 5.10.178-3, 5.10.191-1, 6.1.38-1, 6.1.52-1, 6.5.3-1 or later.