First published: Wed May 25 2022(Updated: )
An issue was discovered in the Linux Kernel from 4.18 to 4.19, an improper update of sock reference in TCP pacing can lead to memory/netns leak, which can be used by remote clients.
Credit: security@openanolis.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Kernel | >=4.18<=4.19 | |
NetApp Active IQ Unified Manager for VMware vSphere | ||
NetApp ONTAP Mediator | ||
NetApp E-Series SANtricity OS Controller | >=11.0<=11.70.2 | |
NetApp Management Services for Element Software | ||
NetApp SolidFire & HCI Management Node | ||
NetApp SolidFire & HCI Storage Node | ||
NetApp StorageGRID Webscale | ||
NetApp HCI Bootstrap OS | ||
NetApp HCI Compute Node | ||
NetApp H300S Firmware | ||
NetApp H300S Firmware | ||
NetApp H500e Firmware | ||
NetApp H500e Firmware | ||
NetApp H700S | ||
NetApp H700S | ||
NetApp H300E | ||
NetApp H300E Firmware | ||
NetApp H500S Firmware | ||
NetApp H500e Firmware | ||
NetApp H700E | ||
NetApp H700E | ||
NetApp H410S | ||
NetApp H410S Firmware | ||
NetApp H410C | ||
NetApp H410C Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-1678 is high with a CVSS score of 7.5.
The affected software includes Linux Kernel versions 4.18 to 4.19, Apple iPadOS, Netapp Cloud Volumes Ontap Mediator, NetApp E-Series SANtricity OS Controller, Netapp Element Software, Netapp Hci Management Node, Netapp Solidfire, Netapp Storagegrid, and Netapp Bootstrap Os.
CVE-2022-1678 can be exploited by remote clients using an improper update of sock reference in TCP pacing, leading to a memory/netns leak.
The CWE ID of CVE-2022-1678 is 911.
More information about CVE-2022-1678 can be found at the following references: [Reference 1](https://anas.openanolis.cn/cves/detail/CVE-2022-1678), [Reference 2](https://anas.openanolis.cn/errata/detail/ANSA-2022:0143), [Reference 3](https://bugzilla.openanolis.cn/show_bug.cgi?id=61)