SB2024062693 - Buffer overflow in Linux kernel mm
Published: June 26, 2024 Updated: May 13, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Buffer overflow (CVE-ID: CVE-2022-48659)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to memory corruption within the create_unique_id() and sysfs_slab_add() functions in mm/slub.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/e9219fa63c5c25804af82c7aa54d1ec770ebe457
- https://git.kernel.org/stable/c/a1d83a19cec3bfeb2b3547a1f7631e432a766d1c
- https://git.kernel.org/stable/c/e996821717c5cf8aa1e1abdb6b3d900a231e3755
- https://git.kernel.org/stable/c/016b150992eebc32c4a18f783cf2bb6e2545a3d9
- https://git.kernel.org/stable/c/379ac7905ff3f0a6a4e507d3e9f710ec4fab9124
- https://git.kernel.org/stable/c/2d6e55e0c03804e1e227b80a5746e086d6c6696c
- https://git.kernel.org/stable/c/02bcd951aa3c2cea95fb241c20802e9501940296
- https://git.kernel.org/stable/c/7e9c323c52b379d261a72dc7bd38120a761a93cd
- https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.295
- https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.260
- https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.330
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.146
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.71
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.19.12
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.215
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.0