Review reviewHigh

CVE-2022-48771

Linux Linux, linux kernel

In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Fix stale file descriptors on failed usercopy A failing usercopy of the fence_rep object will lead to a stale entry in the file descriptor table as put_unused_fd() won't release it. This enables userland to refer to a dangling 'file' object through that still valid file descriptor, leading to all kinds of use-after-free exploitation scenarios. Fix this by deferring the call to fd_install() until after the usercopy has succeeded.

CVSS
7.8
EPSS
0.21%
11.6% percentile
CISA KEV
Not listed
Published
2024.06.20
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.21%
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Fix stale file descriptors on failed usercopy A failing usercopy of the fence_rep object will lead to a stale entry in the file descriptor table as put_unused_fd() won't release it. This enables userland to refer to a dangling 'file' object through that still valid file descriptor, leading to all kinds of use-after-free exploitation scenarios. Fix this by deferring the call to fd_install() until after the usercopy has succeeded.

Affected product and versions

Product
Linux Linux, linux kernel
Affected versions
>= c906965dee22d5e95d0651759ba107b420212a9f < e8d092a62449dcfc73517ca43963d2b8f44d0516, >= c906965dee22d5e95d0651759ba107b420212a9f < 0008a0c78fc33a84e2212a7c04e6b21a36ca6f4d, >= c906965dee22d5e95d0651759ba107b420212a9f < 84b1259fe36ae0915f3d6ddcea6377779de48b82, >= c906965dee22d5e95d0651759ba107b420212a9f < ae2b20f27732fe92055d9e7b350abc5cdf3e2414, >= c906965dee22d5e95d0651759ba107b420212a9f < 6066977961fc6f437bc064f628cf9b0e4571c56c, >= c906965dee22d5e95d0651759ba107b420212a9f < 1d833b27fb708d6fdf5de9f6b3a8be4bd4321565, >= c906965dee22d5e95d0651759ba107b420212a9f < a0f90c8815706981c483a652a6aefca51a5e191c, >= 4.14, >= 4.14 < 4.14.264, >= 4.15 < 4.19.227, >= 4.20 < 5.4.175, >= 5.5 < 5.10.95, >= 5.11 < 5.15.18, >= 5.16 < 5.16.4, 5.17
Fixed versions
4.14.264, 4.19.227, 5.4.175, 5.10.95, 5.15.18, 5.16.4

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, linux kernel and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-416
CVE-2022-48771 — Linux Linux, linux kernel | SECUFOCUS NOW