Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: lockd: set other missing fields when unlocking files vfs_lock_file() expects the struct file_lock to be fully initialised by the caller. Re-exported NFSv3 has been seen to Oops if the fl_file field is NULL.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 5.15.56, < 5.15.86 |
References
- https://git.kernel.org/stable/c/18ebd35b61b4693a0ddc270b6d4f18def232e770Patch
- https://git.kernel.org/stable/c/31c93ee5f1e4dc278b562e20f3c3274ac34997f3Patch
- https://git.kernel.org/stable/c/688575aef211b0986fc51010116f5888a99d76a2Patch
- https://git.kernel.org/stable/c/95d42a8d3d4ae84a0bd3ee23e1fee240cdf0a9f0Patch
- https://git.kernel.org/stable/c/d7aa9f7778316beb690f6e2763b6d672ad8b256fPatch
FAQ
What is CVE-2022-50302?
CVE-2022-50302 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In the Linux kernel, the following vulnerability has been resolved: lockd: set other missing fields when unlocking files vfs_lock_file() expects the struct file_lock to be fully initialised by the c...
How severe is CVE-2022-50302?
CVE-2022-50302 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-50302?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.