VulnerabilityModified
CVE-2022-4139
An incorrect TLB flush issue was found in the Linux kernel’s GPU i915 kernel driver, potentially leading to random memory corruption or data leaks.
HIGH 7.8EPSS 0.25%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.25%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An incorrect TLB flush issue was found in the Linux kernel’s GPU i915 kernel driver, potentially leading to random memory corruption or data leaks. This flaw could allow a local user to crash the system or escalate their privileges on the system.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.25% probability · 17th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-281, CWE-401
- Affected
- linux/linux kernel
- Source
- secalert@redhat.com
References
- https://bugzilla.redhat.com/show_bug.cgi?id=2147572Issue Tracking, Patch, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20230309-0004/Third Party Advisory
- https://www.openwall.com/lists/oss-security/2022/11/30/1Mailing List, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2147572Issue Tracking, Patch, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20230309-0004/Third Party Advisory
- https://www.openwall.com/lists/oss-security/2022/11/30/1Mailing List, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.