First published: Mon Aug 29 2022(Updated: )
A flaw in net_rds_alloc_sgs() in Oracle Linux kernels allows unprivileged local users to crash the machine. CVSS 3.1 Base Score 6.2 (Availability impacts). CVSS Vector (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Linux |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-21385 is a vulnerability in net_rds_alloc_sgs() in Oracle Linux kernels that allows unprivileged local users to crash the machine.
The severity of CVE-2022-21385 is medium with a CVSS 3.1 Base Score of 6.2 (Availability impacts).
CVE-2022-21385 impacts Oracle Linux kernels allowing unprivileged local users to crash the machine.
Unprivileged local users can exploit CVE-2022-21385 by triggering the flaw in net_rds_alloc_sgs().
Yes, a fix for CVE-2022-21385 is available. Please refer to the reference link for more information.