CVE-2022-24448

CVSS v3.1 3.3 (Low)
33% Progress
CVSS v2.0 1.9 (Low)
19% Progress
EPSS 0.05 % (19th)
0.05% Progress
Affected Products 2
Advisories 42

An issue was discovered in fs/nfs/dir.c in the Linux kernel before 5.16.5. If an application sets the O_DIRECTORY flag, and tries to open a regular file, nfs_atomic_open() performs a regular lookup. If a regular file is found, ENOTDIR should occur, but the server instead returns uninitialized data in the file descriptor.

Weaknesses
CWE-755
Improper Handling of Exceptional Conditions
CWE-908
Use of Uninitialized Resource
CVE Status
PUBLISHED
CNA
MITRE
Published Date
2022-02-04 20:15:08
(2 years ago)
Updated Date
2023-11-07 03:44:30
(10 months ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Linux Kernel prior 5.16.5 version cpe:2.3:o:linux:linux_kernel < 5.16.5

Configuration #2

    CPE23 From Up To
  Debian Linux 9.0 cpe:2.3:o:debian:debian_linux:9.0
  Debian Linux 10.0 cpe:2.3:o:debian:debian_linux:10.0
  Debian Linux 11.0 cpe:2.3:o:debian:debian_linux:11.0
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...