SB2024060884 - Information disclosure in Linux kernel sched
Published: June 8, 2024 Updated: May 13, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Information disclosure (CVE-ID: CVE-2022-48639)
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to information disclosure within the net/sched/cls_api.c. A local user can gain access to sensitive information.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/903f7d322c17d8e306d766404b4604e81653902a
- https://git.kernel.org/stable/c/8844c750eeb03452e2b3319c27a526f447b82596
- https://git.kernel.org/stable/c/f8162aed962be8fa07445b2b5928e84ab40dd8d7
- https://git.kernel.org/stable/c/0559d91ee3a2cd81b15ad5cd507539d6da867f88
- https://git.kernel.org/stable/c/c2e1cfefcac35e0eea229e148c8284088ce437b5
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.146
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.71
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.19.12
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.215
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.0