CVE-2022-3594

ECS: Improper Resource Shutdown or Release (CVE-2022-3594)

mediumEPSS 2.5%

Affected

  • Dell/ECS 3.8.1.0..*

Description

A vulnerability was found in intr_callback in drivers/net/usb/r8152.c in the BPF component in the Linux Kernel. The manipulation leads to logging excessive data, where an attack can be launched remotely.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

DellECS
3.8.1.0

Metrics

5.3
Source: cna-v3
84.1 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
Show all metrics
Severity
medium
no public PoC known
2.5 %
Moderate — model estimates 1-10% exploitation likelihood.
Published
2022-10-18 00:00 UTC
CWE-404

Weakness classes (CWE)

  • CWE-404Class

    Improper Resource Shutdown or Release

    The product does not release or incorrectly releases a resource before it is made available for re-use.

    cwe.mitre.org →

References & sources