6.9
CVSSv2

CVE-2022-28796

Published: 08/04/2022 Updated: 29/08/2023
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
CVSS v3 Base Score: 7 | Impact Score: 5.9 | Exploitability Score: 1
VMScore: 614
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

jbd2_journal_wait_updates in fs/jbd2/transaction.c in the Linux kernel prior to 5.17.1 has a use-after-free caused by a transaction_t race condition.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

linux linux kernel

redhat enterprise linux 7.0

redhat enterprise linux 6.0

fedoraproject fedora 35

netapp solidfire & hci management node -

netapp solidfire, enterprise sds & hci storage node -

netapp active iq unified manager -

netapp hci compute node firmware -

netapp h300s firmware -

netapp h500s firmware -

netapp h700s firmware -

netapp h300e firmware -

netapp h500e firmware -

netapp h700e firmware -

netapp h410s firmware -

netapp h410c firmware -

Vendor Advisories

A use-after-free flaw was found in the Linux kernel’s journaling layer of the ext4 and OCFS2 file system functionality in the way a user can trigger a race condition during writing to the file system This flaw allows a local user to crash or potentially escalate their privileges on the system ...