CVE-2022-48667

Description

A vulnerability was found in the Linux kernel's Server Message Block version 3 (SMB3 ) protocol, specifically related to the insert range operation. This issue occurs when cached regions affected by the insert range operation are not properly discarded, which could lead to temporary file data corruption.

Statement

The problem was resolved by making sure that the affected cached regions are handled correctly to prevent data corruption. Additionally, some minor code cleanup was included to improve efficiency, such as reducing unnecessary inode size rereads.

Common Vulnerability Scoring System (CVSS) Score Details

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

The following CVSS metrics and score provided are preliminary and subject to review.

CVSS v3 Score Breakdown

Red HatNVDcve.org
Base Score6.13.3N/A
Attack VectorLocalLocalN/A
Attack ComplexityLowLowN/A
Privileges RequiredLowLowN/A
User InteractionNoneNoneN/A
ScopeUnchangedUnchangedN/A
ConfidentialityNoneNoneN/A
Integrity ImpactLowNoneN/A
Availability ImpactHighLowN/A

Vector

Red Hat: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H

NVD: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Understanding the Weakness (CWE)

Integrity

Technical Impact: Alter Execution Logic

Frequently Asked Questions

Want to get errata notifications? Sign up here.