U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2022-48832

Change History

New CVE Received by NIST 7/16/2024 8:15:06 AM

Action Type Old Value New Value
Added Description

								
							
							
						
In the Linux kernel, the following vulnerability has been resolved:

audit: don't deref the syscall args when checking the openat2 open_how::flags

As reported by Jeff, dereferencing the openat2 syscall argument in
audit_match_perm() to obtain the open_how::flags can result in an
oops/page-fault.  This patch fixes this by using the open_how struct
that we store in the audit_context with audit_openat2_how().

Independent of this patch, Richard Guy Briggs posted a similar patch
to the audit mailing list roughly 40 minutes after this patch was
posted.
Added Reference

								
							
							
						
kernel.org https://git.kernel.org/stable/c/310c9ddfdf1f8d3c9834f02175eae79c8b254b6c [No types assigned]
Added Reference

								
							
							
						
kernel.org https://git.kernel.org/stable/c/7a82f89de92aac5a244d3735b2bd162c1147620c [No types assigned]