5.5
CVSSv3

CVE-2022-40768

Published: 18/09/2022 Updated: 25/03/2024
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

drivers/scsi/stex.c in the Linux kernel up to and including 5.19.9 allows local users to obtain sensitive information from kernel memory because stex_queuecommand_lck lacks a memset for the PASSTHRU_CMD case.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

linux linux kernel

fedoraproject fedora 35

fedoraproject fedora 36

fedoraproject fedora 37

debian debian linux 10.0

Vendor Advisories

In v4l2_m2m_querybuf of v4l2-mem2memc, there is a possible out of bounds write due to improper input validation This could lead to local escalation of privilege with System execution privileges needed User interaction is not needed for exploitationProduct: AndroidVersions: Android kernelAndroid ID: A-223375145References: Upstream kernel (CVE-20 ...
Several security issues were fixed in the Linux kernel ...
Several security issues were fixed in the Linux kernel ...
Several security issues were fixed in the Linux kernel ...
Several security issues were fixed in the Linux kernel ...
Several security issues were fixed in the Linux kernel ...
Several security issues were fixed in the Linux kernel ...
Several security issues were fixed in the Linux kernel ...
Several security issues were fixed in the Linux kernel ...
Several security issues were fixed in the Linux kernel ...
Several security issues were fixed in the Linux kernel ...
Description The MITRE CVE dictionary describes this issue as: drivers/scsi/stexc in the Linux kernel through 5199 allows local users to obtain sensitive information from kernel memory because stex_queuecommand_lck lacks a memset for the PASSTHRU_CMD case ...
A vulnerability was found in Linux Kernel It has been classified as problematic Affected is the function nilfs_bmap_lookup_at_level of the file fs/nilfs2/inodec of the component nilfs2 The manipulation leads to null pointer dereference It is possible to launch the attack remotely It is recommended to apply a patch to fix this issue The ident ...
A vulnerability was found in Linux Kernel It has been classified as problematic Affected is the function nilfs_bmap_lookup_at_level of the file fs/nilfs2/inodec of the component nilfs2 The manipulation leads to null pointer dereference It is possible to launch the attack remotely It is recommended to apply a patch to fix this issue The ident ...
A vulnerability was found in Linux Kernel It has been declared as problematic Affected by this vulnerability is the function intr_callback of the file drivers/net/usb/r8152c of the component BPF The manipulation leads to logging of excessive data The attack can be launched remotely It is recommended to apply a patch to fix this issue The ass ...
drivers/scsi/stexc in the Linux kernel through 5199 allows local users to obtain sensitive information from kernel memory because stex_queuecommand_lck lacks a memset for the PASSTHRU_CMD case (CVE-2022-40768) ...
Severity Unknown Remote Unknown Type Unknown Description AVG-2837 linux 6012-1 62-1 High Unknown AVG-2836 linux-zen 6012-1 62-1 High Unknown ...