CVE-2022-4379
HIGHLinux Kernel >=5.6 <5.10.177 - Use-After-Free in __nfs42_ssc_open
Title source: llmDescription
A use-after-free vulnerability was found in __nfs42_ssc_open() in fs/nfs/nfs4file.c in the Linux kernel. This flaw allows an attacker to conduct a remote denial
References (7)
Core 7
Core References
Patch, Vendor Advisory
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=75333d48f92256a0dec91dbf07835e804fc411c0
Patch, Vendor Advisory
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=aeba12b26c79fc35e07e511f692a8907037d95da
Mailing List, Third Party Advisory
https://lists.debian.org/debian-lts-announce/2023/05/msg00005.html
Mailing List, Third Party Advisory
https://seclists.org/oss-sec/2022/q4/185
Vendor Advisory
https://security.netapp.com/advisory/ntap-20230223-0004/
Mailing List, Third Party Advisory vendor-advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RAVD6JIILAVSRHZ4VXSV3RAAGUXKVXZA/
Mailing List, Third Party Advisory vendor-advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LECFVUHKIRBV5JJBE3KQCLGKNYJPBRCN/
Scores
CVSS v3
7.5
EPSS
0.0028
EPSS Percentile
51.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-416
Status
published
Products (3)
fedoraproject/fedora
36
fedoraproject/fedora
37
linux/linux_kernel
5.6 - 5.10.177
Published
Jan 10, 2023
Tracked Since
Feb 18, 2026