First published: Thu Sep 01 2022(Updated: )
A vulnerability was found in follow_page_pte in mm/gup.c in the Linux Kernel due to a race problem, which can poison the page table entry, and cause denial-of-service problem. Reference: <a href="https://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf-next.git/commit/?id=fac35ba763ed07ba93154c95ffc0c4a55023707f">https://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf-next.git/commit/?id=fac35ba763ed07ba93154c95ffc0c4a55023707f</a>
Credit: cna@vuldb.com cna@vuldb.com cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/kernel-rt | <0:4.18.0-477.10.1.rt7.274.el8_8 | 0:4.18.0-477.10.1.rt7.274.el8_8 |
redhat/kernel | <0:4.18.0-477.10.1.el8_8 | 0:4.18.0-477.10.1.el8_8 |
redhat/kernel | <0:5.14.0-284.11.1.el9_2 | 0:5.14.0-284.11.1.el9_2 |
redhat/kernel-rt | <0:5.14.0-284.11.1.rt14.296.el9_2 | 0:5.14.0-284.11.1.rt14.296.el9_2 |
redhat/kernel | <6.1 | 6.1 |
Linux Kernel | >=5.1<5.4.228 | |
Linux Kernel | >=5.5<5.10.159 | |
Linux Kernel | >=5.11<5.15.78 | |
Linux Kernel | >=5.16<5.19.17 | |
Linux Kernel | >=6.0<6.0.3 | |
Debian Debian Linux | =11.0 | |
debian/linux | 5.10.223-1 5.10.226-1 6.1.123-1 6.1.119-1 6.12.11-1 6.12.12-1 |
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2022-3623 is classified as a denial-of-service vulnerability due to a race condition in the Linux Kernel.
To fix CVE-2022-3623, update your Linux Kernel to kernel-rt versions 0:4.18.0-477.10.1.rt7.274.el8_8 or 0:5.14.0-284.11.1.rt14.296.el9_2, or apply applicable updates from your distribution.
CVE-2022-3623 affects Linux Kernel versions 5.1 up to 5.4.228, 5.5 up to 5.10.159, 5.11 up to 5.15.78, and 5.16 up to 5.19.17.
The primary impact of CVE-2022-3623 is that it can lead to denial-of-service situations due to poisoned page table entries.
Yes, CVE-2022-3623 is exploitable remotely under certain conditions, posing significant risk to vulnerable systems.