CVE-2022-1678: High severity linux kernel vulnerability
An issue was discovered in the Linux Kernel from 4.18 to 4.19, an improper update of sock reference in TCP pacing can lead to memory/netns leak, which can be used by remote clients.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2022-1678?
The severity of CVE-2022-1678 is high with a CVSS score of 7.5.
What is the affected software of CVE-2022-1678?
The affected software includes Linux Kernel versions 4.18 to 4.19, Apple iPadOS, Netapp Cloud Volumes Ontap Mediator, NetApp E-Series SANtricity OS Controller, Netapp Element Software, Netapp Hci Management Node, Netapp Solidfire, Netapp Storagegrid, and Netapp Bootstrap Os.
How can CVE-2022-1678 be exploited?
CVE-2022-1678 can be exploited by remote clients using an improper update of sock reference in TCP pacing, leading to a memory/netns leak.
What is the Common Weakness Enumeration (CWE) ID of CVE-2022-1678?
The CWE ID of CVE-2022-1678 is 911.
Where can I find more information about CVE-2022-1678?
More information about CVE-2022-1678 can be found at the following references: [Reference 1](https://anas.openanolis.cn/cves/detail/CVE-2022-1678), [Reference 2](https://anas.openanolis.cn/errata/detail/ANSA-2022:0143), [Reference 3](https://bugzilla.openanolis.cn/show_bug.cgi?id=61)