CVE-2022-21385: Medium severity oracle linux vulnerability
Published Aug 29, 2022
·Updated
A flaw in netrdsallocsgs() in Oracle Linux kernels allows unprivileged local users to crash the machine. CVSS 3.1 Base Score 6.2 (Availability impacts). CVSS Vector (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Affected Software
1 affected component
ORACLE Linux
Remediation
Event History
Aug 29, 2022
CVE Published
via MITRE·08:35 PM
Data Sourced
via MITRE·08:35 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-21385?
CVE-2022-21385 is a vulnerability in net_rds_alloc_sgs() in Oracle Linux kernels that allows unprivileged local users to crash the machine.
2
What is the severity of CVE-2022-21385?
The severity of CVE-2022-21385 is medium with a CVSS 3.1 Base Score of 6.2 (Availability impacts).
3
How does CVE-2022-21385 impact Oracle Linux?
CVE-2022-21385 impacts Oracle Linux kernels allowing unprivileged local users to crash the machine.
4
How can unprivileged local users exploit CVE-2022-21385?
Unprivileged local users can exploit CVE-2022-21385 by triggering the flaw in net_rds_alloc_sgs().
5
Is there a fix available for CVE-2022-21385?
Yes, a fix for CVE-2022-21385 is available. Please refer to the reference link for more information.