CVE-2022-28893

The SUNRPC subsystem in the Linux kernel through 5.17.2 can call xs_xprt_free before ensuring that sockets are in the intended state.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:netapp:solidfire\,_enterprise_sds_\&_hci_storage_node:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:solidfire_\&_hci_management_node:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:netapp:hci_compute_node_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:hci_compute_node:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h300s:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h500s:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h700s:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:netapp:h300e_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h300e:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:netapp:h500e_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h500e:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:netapp:h700e_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h700e:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h410s:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:netapp:h410c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h410c:-:*:*:*:*:*:*:*

Configuration 12 (hide)

cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*

History

08 Oct 2022, 03:21

Type Values Removed Values Added
First Time Netapp solidfire\, Enterprise Sds \& Hci Storage Node
Netapp h500e
Netapp h700e Firmware
Netapp h500s
Netapp h500e Firmware
Netapp h410s Firmware
Debian
Netapp h300e
Netapp h300e Firmware
Netapp solidfire \& Hci Management Node
Netapp h700s
Netapp h300s
Netapp h700e
Netapp h410c
Netapp h410c Firmware
Debian debian Linux
Netapp
Netapp h300s Firmware
Netapp hci Compute Node
Netapp h700s Firmware
Netapp hci Compute Node Firmware
Netapp h410s
Netapp h500s Firmware
References (CONFIRM) https://security.netapp.com/advisory/ntap-20220526-0002/ - (CONFIRM) https://security.netapp.com/advisory/ntap-20220526-0002/ - Third Party Advisory
References (DEBIAN) https://www.debian.org/security/2022/dsa-5161 - (DEBIAN) https://www.debian.org/security/2022/dsa-5161 - Mailing List, Third Party Advisory
CPE cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h500e:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h300e_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h500e_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:hci_compute_node_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h700e_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h500s:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h300e:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h700e:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h410s:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:solidfire\,_enterprise_sds_\&_hci_storage_node:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:solidfire_\&_hci_management_node:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h410c:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h700s:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:hci_compute_node:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h300s:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h410c_firmware:-:*:*:*:*:*:*:*

13 Jun 2022, 11:15

Type Values Removed Values Added
References
  • (DEBIAN) https://www.debian.org/security/2022/dsa-5161 -

26 May 2022, 08:15

Type Values Removed Values Added
References
  • (CONFIRM) https://security.netapp.com/advisory/ntap-20220526-0002/ -

15 Apr 2022, 03:17

Type Values Removed Values Added
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
First Time Linux linux Kernel
Linux
CVSS v2 : unknown
v3 : unknown
v2 : 7.2
v3 : 7.8
CWE CWE-416
References (MLIST) http://www.openwall.com/lists/oss-security/2022/04/11/5 - (MLIST) http://www.openwall.com/lists/oss-security/2022/04/11/5 - Mailing List, Patch, Third Party Advisory
References (MLIST) http://www.openwall.com/lists/oss-security/2022/04/11/3 - (MLIST) http://www.openwall.com/lists/oss-security/2022/04/11/3 - Mailing List, Patch, Third Party Advisory
References (MISC) https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=1a3b1bba7c7a5eb8a11513cf88427cb9d77bc60a - (MISC) https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=1a3b1bba7c7a5eb8a11513cf88427cb9d77bc60a - Patch, Third Party Advisory
References (MLIST) http://www.openwall.com/lists/oss-security/2022/04/11/4 - (MLIST) http://www.openwall.com/lists/oss-security/2022/04/11/4 - Issue Tracking, Mailing List, Patch

11 Apr 2022, 21:15

Type Values Removed Values Added
References
  • (MLIST) http://www.openwall.com/lists/oss-security/2022/04/11/5 -

11 Apr 2022, 15:15

Type Values Removed Values Added
References
  • (MLIST) http://www.openwall.com/lists/oss-security/2022/04/11/3 -
  • (MLIST) http://www.openwall.com/lists/oss-security/2022/04/11/4 -

11 Apr 2022, 09:13

Type Values Removed Values Added
New CVE

Information

Published : 2022-04-11 05:15

Updated : 2023-12-10 14:22


NVD link : CVE-2022-28893

Mitre link : CVE-2022-28893

CVE.ORG link : CVE-2022-28893


JSON object : View

Products Affected

netapp

  • h700s_firmware
  • h700e
  • hci_compute_node
  • h700e_firmware
  • h700s
  • h300s_firmware
  • hci_compute_node_firmware
  • h300s
  • solidfire_\&_hci_management_node
  • h300e
  • h500e_firmware
  • h410c_firmware
  • h500s
  • h410c
  • h410s
  • solidfire\,_enterprise_sds_\&_hci_storage_node
  • h410s_firmware
  • h500s_firmware
  • h300e_firmware
  • h500e

debian

  • debian_linux

linux

  • linux_kernel
CWE
CWE-416

Use After Free