CVE-2022-0854
MEDIUMLinux Kernel < 5.16 - Information Disclosure
Title source: ruleDescription
A memory leak flaw was found in the Linux kernel’s DMA subsystem, in the way a user calls DMA_FROM_DEVICE. This flaw allows a local user to read random memory from the kernel space.
References (4)
Scores
CVSS v3
5.5
EPSS
0.0001
EPSS Percentile
2.5%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Classification
CWE
CWE-401
CWE-200
Status
published
Affected Products (12)
linux/linux_kernel
< 5.16
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
debian/debian_linux
debian/debian_linux
debian/debian_linux
Timeline
Published
Mar 23, 2022
Tracked Since
Feb 18, 2026