UBUNTU-CVE-2022-1116
Vulnerability Summary
Timeline
Description
Integer Overflow or Wraparound vulnerability in io_uring of Linux Kernel allows local attacker to cause memory corruption and escalate privileges to root. This issue affects: Linux Kernel versions prior to 5.4.189; version 5.4.24 and later versions.
CVSS Metrics
- v3.1•HIGH•Score: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Systems
- ubuntu•linux
< 5.4.0-113.127
- ubuntu•linux-aws
< 5.4.0-1075.80
- ubuntu•linux-aws-5.0
all
- ubuntu•linux-aws-5.11
all
- ubuntu•linux-aws-5.3
all
- ubuntu•linux-aws-5.4
< 5.4.0-1075.80~18.04.1
- ubuntu•linux-aws-5.8
all
- ubuntu•linux-aws-fips
< 5.4.0-1078.84+fips1 | all
- ubuntu•linux-azure
all | < 5.4.0-1080.83
- ubuntu•linux-azure-5.11
all
- ubuntu•linux-azure-5.3
all
- ubuntu•linux-azure-5.4
< 5.4.0-1080.83~18.04.2
- ubuntu•linux-azure-5.8
all
- ubuntu•linux-azure-edge
all
- ubuntu•linux-azure-fips
< 5.4.0-1080.83+fips1 | all
- ubuntu•linux-bluefield
< 5.4.0-1036.39
- ubuntu•linux-fips
< 5.4.0-1051.57 | all
- ubuntu•linux-gcp
all | < 5.4.0-1075.80
- ubuntu•linux-gcp-5.11
all
- ubuntu•linux-gcp-5.3
all
- ubuntu•linux-gcp-5.4
< 5.4.0-1075.80~18.04.1
- ubuntu•linux-gcp-5.8
all
- ubuntu•linux-gcp-fips
< 5.4.0-1075.80+fips1 | all
- ubuntu•linux-gke
< 5.4.0-1072.77
- ubuntu•linux-gke-4.15
all
- ubuntu•linux-gke-5.4
< 5.4.0-1072.77~18.04.1
- ubuntu•linux-gkeop
< 5.4.0-1043.44
- ubuntu•linux-gkeop-5.4
< 5.4.0-1043.44~18.04.1
- ubuntu•linux-hwe
all
- ubuntu•linux-hwe-5.11
all
- ubuntu•linux-hwe-5.4
< 5.4.0-113.127~18.04.1
- ubuntu•linux-hwe-5.8
all
- ubuntu•linux-hwe-edge
all
- ubuntu•linux-ibm
< 5.4.0-1023.25
- ubuntu•linux-ibm-5.4
< 5.4.0-1023.25~18.04.1
- ubuntu•linux-intel-iot-realtime
all
- ubuntu•linux-iot
< 5.4.0-1004.6
- ubuntu•linux-kvm
< 5.4.0-1065.68
- ubuntu•linux-nvidia
all
- ubuntu•linux-oem
all
- ubuntu•linux-oem-5.10
all
- ubuntu•linux-oem-5.13
all
- ubuntu•linux-oem-5.6
all
- ubuntu•linux-oracle
< 5.4.0-1073.79
- ubuntu•linux-oracle-5.0
all
- ubuntu•linux-oracle-5.11
all
- ubuntu•linux-oracle-5.3
all
- ubuntu•linux-oracle-5.4
< 5.4.0-1073.79~18.04.1
- ubuntu•linux-oracle-5.8
all
- ubuntu•linux-raspi
< 5.4.0-1062.70
Showing first 50 affected entries in server-rendered view.
References (6)
- https://ubuntu.com/security/CVE-2022-1116
- https://kernel.dance/#1a623d361ffe5cecd4244a02f449528416360038
- https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/fs/io_uring.c?h=v5.4.189&id=1a623d361ffe5cecd4244a02f449528416360038
- https://ubuntu.com/security/notices/USN-5442-1
- https://ubuntu.com/security/notices/USN-5442-2
- https://www.cve.org/CVERecord?id=CVE-2022-1116