VulnerabilityModified
CVE-2022-50302
In the Linux kernel, the following vulnerability has been resolved: lockd: set other missing fields when unlocking files vfs_lock_file() expects the struct file_lock to be fully initialised by the caller.
MEDIUM 5.5EPSS 0.36%
Does this matter?
Lower severity and a low EPSS score (0.36%). Track it; it rarely justifies an emergency change on its own.
Description
In the Linux kernel, the following vulnerability has been resolved: lockd: set other missing fields when unlocking files vfs_lock_file() expects the struct file_lock to be fully initialised by the caller. Re-exported NFSv3 has been seen to Oops if the fl_file field is NULL.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.36% probability · 29th percentile
- CISA KEV
- Not listed
- Affected
- linux/linux kernel
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/18ebd35b61b4693a0ddc270b6d4f18def232e770Patch
- https://git.kernel.org/stable/c/31c93ee5f1e4dc278b562e20f3c3274ac34997f3Patch
- https://git.kernel.org/stable/c/688575aef211b0986fc51010116f5888a99d76a2Patch
- https://git.kernel.org/stable/c/95d42a8d3d4ae84a0bd3ee23e1fee240cdf0a9f0Patch
- https://git.kernel.org/stable/c/d7aa9f7778316beb690f6e2763b6d672ad8b256fPatch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.