CVE-2022-1462 - CERT CVE
ID CVE-2022-1462
Sažetak An out-of-bounds read flaw was found in the Linux kernel’s TeleTYpe subsystem. The issue occurs in how a user triggers a race condition using ioctls TIOCSPTLCK and TIOCGPTPEER and TIOCSTI and TCXONC with leakage of memory in the flush_to_ldisc function. This flaw allows a local user to crash the system or read unauthorized random data from memory.
Reference
CVSS
Base: 3.3
Impact: 4.9
Exploitability:3.4
Pristup
VektorSloženostAutentikacija
LOCAL MEDIUM NONE
Impact
PovjerljivostCjelovitostDostupnost
PARTIAL NONE PARTIAL
CVSS vektor AV:L/AC:M/Au:N/C:P/I:N/A:P
Zadnje važnije ažuriranje 29-10-2022 - 02:45
Objavljeno 02-06-2022 - 14:15