CVE-2022-3566
Vulnerability Summary
Timeline
Description
A vulnerability was identified in Linux Kernel up to 4.19.316/5.4.278/5.10.220/5.15.161. This impacts the function tcp_getsockopt/tcp_setsockopt of the component TCP Handler. Such manipulation leads to race condition. A high complexity level is associated with this attack. The exploitability is said to be difficult. The vulnerability was introduced in 2.6.12, commit 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 ("Linux-2.6.12-rc2"). Upgrading to version 4.19.317, 5.4.279, 5.10.221, 5.15.162 and 6.1 will fix this issue. The name of the patch is fcd31dd8291b23d713245947ec2b2d99ef07aef2/3b32f265805a49071e2c4568a524398ba22bf93c/d529193eae979a7bf2255cd9fe68b7af7a1c91b3/5bb642cc3355ffd3c8bca0a8bd8e6e65bcc2091c/f49cd2f4d6170d27a2c61f1fecb03d8a70c91f57. The affected component should be upgraded.
CVSS Metrics
- v4.0•LOW•Score: 2.1CVSS:4.0/AV:A/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X
- v4.0•LOW•Score: 2.1CVSS:4.0/AV:A/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- v4.0•LOW•Score: 2.1CVSS:4.0/AV:A/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
- v3.1•MEDIUM•Score: 4.6CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C
- v3.1•HIGH•Score: 7.1CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- v3.0•MEDIUM•Score: 4.6CVSS:3.0/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C
- v2.0•MEDIUM•Score: 4AV:A/AC:H/Au:S/C:P/I:P/A:P/E:ND/RL:OF/RC:C
- v2.0•MEDIUM•Score: 4AV:A/AC:H/Au:S/C:P/I:P/A:P
EPSS Trends
Current EPSS score: 0.69%• Percentile: 51%
Techniques & Countermeasures
- CWE-362•Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.
Affected Systems
- chainguard•hyperv-daemons-6.18
< 0
- chainguard•hyperv-daemons-generic
< 0
- chainguard•linux-aws-6.12
< 6.12.65-r0 | < 0
- chainguard•linux-aws-6.12-boot-installed
< 0
- chainguard•linux-aws-6.12-fips-boot-installed
< 0
- chainguard•linux-aws-6.12-headers
< 0
- chainguard•linux-aws-6.12-modules
< 0
- chainguard•linux-aws-6.18
< 0 | < 6.18.10-r0
- chainguard•linux-aws-6.18-boot-installed
< 0
- chainguard•linux-aws-6.18-fips-boot-installed
< 0
- chainguard•linux-aws-6.18-headers
< 0
- chainguard•linux-aws-6.18-modules
< 0
- chainguard•linux-aws-generic
< 0 | < 6.18.5-r0
- chainguard•linux-aws-generic-boot-installed
< 0
- chainguard•linux-aws-generic-fips-boot-installed
< 0
- chainguard•linux-aws-generic-headers
< 0
- chainguard•linux-aws-generic-modules
< 0
- chainguard•linux-azure-6.12
< 0 | < 6.12.65-r1
- chainguard•linux-azure-6.18
< 0
- chainguard•linux-azure-6.18-boot-installed
< 0
- chainguard•linux-azure-6.18-fips-boot-installed
< 0
- chainguard•linux-azure-6.18-headers
< 0
- chainguard•linux-azure-6.18-modules
< 0
- chainguard•linux-azure-generic
< 0 | < 6.18.5-r0
- chainguard•linux-azure-generic-boot-installed
< 0
- chainguard•linux-azure-generic-fips-boot-installed
< 0
- chainguard•linux-azure-generic-headers
< 0
- chainguard•linux-azure-generic-modules
< 0
- chainguard•linux-gcp-6.12
< 6.12.65-r0 | < 0
- chainguard•linux-gcp-6.18
< 0 | < 6.18.10-r0
- chainguard•linux-gcp-6.18-boot-installed
< 0
- chainguard•linux-gcp-6.18-fips-boot-installed
< 0
- chainguard•linux-gcp-6.18-headers
< 0
- chainguard•linux-gcp-6.18-modules
< 0
- chainguard•linux-gcp-generic
< 0 | < 6.18.5-r0
- chainguard•linux-gcp-generic-boot-installed
< 0
- chainguard•linux-gcp-generic-fips-boot-installed
< 0
- chainguard•linux-gcp-generic-headers
< 0
- chainguard•linux-gcp-generic-modules
< 0
- chainguard•linux-qemu-6.12
< 6.12.71-r0
- chainguard•linux-qemu-6.18
< 6.18.10-r0
- chainguard•linux-qemu-generic
< 0 | < 6.18.5-r0
- chainguard•linux-qemu-generic-bootc-boot-installed
< 6.18.5-r0
- chainguard•linux-qemu-melange
< 6.18.16-r0
- chainguard•linux-qemu-rc
< 6.18_rc6-r0 | < 6.18_rc5-r0 | < 6.19_rc2-r0 | < 6.19_rc1-r1 | < 6.19_rc1-r2 | < 6.19_rc3-r0 | < 6.19_rc5-r0 | < 6.18_rc5-r1 | < 6.19_rc1-r0 | < 6.18_rc7-r2 | < 6.19_rc4-r0 | < 6.18_rc7-r3 | < 0
- chainguard•linux-qemu-rc-boot-installed
< 0
- chainguard•linux-qemu-rc-fips-boot-installed
< 0
- chainguard•linux-qemu-rc-headers
< 0
- chainguard•linux-qemu-rc-modules
< 0
- chainguard•linux-vmware-6.12
< 6.12.71-r0
Showing first 50 affected entries in server-rendered view.
References (24)
- https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=f49cd2f4d6170d27a2c61f1fecb03d8a70c91f57
- https://vuldb.com/?id.211089
- https://vuldb.com/vuln/211089
- https://vuldb.com/vuln/211089/cti
- https://vuldb.com/cve/CVE-2022-3566
- https://www.kernel.org/
- https://ubuntu.com/security/CVE-2022-3566
- https://git.kernel.org/linus/f49cd2f4d6170d27a2c61f1fecb03d8a70c91f57
- https://ubuntu.com/security/notices/USN-5754-1
- https://ubuntu.com/security/notices/USN-5755-1
- https://ubuntu.com/security/notices/USN-5756-1
- https://ubuntu.com/security/notices/USN-5757-1
- https://ubuntu.com/security/notices/USN-5757-2
- https://ubuntu.com/security/notices/USN-5758-1
- https://ubuntu.com/security/notices/USN-5756-2
- https://ubuntu.com/security/notices/USN-5755-2
- https://ubuntu.com/security/notices/USN-5754-2
- https://ubuntu.com/security/notices/USN-5773-1
- https://ubuntu.com/security/notices/USN-5756-3
- https://ubuntu.com/security/notices/USN-5774-1
- https://ubuntu.com/security/notices/USN-5779-1
- https://ubuntu.com/security/notices/USN-5789-1
- https://www.cve.org/CVERecord?id=CVE-2022-3566
- https://security-tracker.debian.org/tracker/CVE-2022-3566