Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2022-2959

Description

A race condition was found in the Linux kernel's watch queue due to a missing lock in pipe_resize_ring(). The specific flaw exists within the handling of pipe buffers. The issue results from the lack of proper locking when performing operations on an object. This flaw allows a local user to crash the system or escalate their privileges on the system.

POC

Reference

- https://github.com/torvalds/linux/commit/189b0ddc245139af81198d1a3637cac74f96e13a

Github

- https://github.com/ARPSyndicate/cvemon

- https://github.com/EGI-Federation/SVG-advisories

- https://github.com/OSS-SASM/RhsaCveScanner

- https://github.com/karimhabush/cyberowl