Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: ceph: don't leak snap_rwsem in handle_cap_grant When handle_cap_grant is called on an IMPORT op, then the snap_rwsem is held and the function is expected to release it before returning. It currently fails to do that in all cases which could lead to a deadlock.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 5.8, < 5.10.138 |
References
- https://git.kernel.org/stable/c/58dd4385577ed7969b80cdc9e2a31575aba6c712Patch
- https://git.kernel.org/stable/c/a090cc69699ec2d11b5e34cee8c61f0d4b0068cbPatch
- https://git.kernel.org/stable/c/aee18421bda6bf12a7cba6a3d7751c0e1cfd0094Patch
- https://git.kernel.org/stable/c/f546faa216d0f53a42ca73ba1fd8c48765b22d77Patch
FAQ
What is CVE-2022-50059?
CVE-2022-50059 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In the Linux kernel, the following vulnerability has been resolved: ceph: don't leak snap_rwsem in handle_cap_grant When handle_cap_grant is called on an IMPORT op, then the snap_rwsem is held and t...
How severe is CVE-2022-50059?
CVE-2022-50059 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-50059?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.