CVE-2022-3594
ECS: Improper Resource Shutdown or Release (CVE-2022-3594)
mediumEPSS 2.5%
Affected
- Dell/ECS
3.8.1.0..*
Description
A vulnerability was found in intr_callback in drivers/net/usb/r8152.c in the BPF component in the Linux Kernel. The manipulation leads to logging excessive data, where an attack can be launched remotely.
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
DellECS
3.8.1.0Metrics
84.1 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
Show all metrics
Severity
medium
84.69
no public PoC known
5.3
Published
2022-10-18 00:00 UTC
CWE-404
Weakness classes (CWE)
CWE-404Class
Improper Resource Shutdown or Release
The product does not release or incorrectly releases a resource before it is made available for re-use.
cwe.mitre.org →
References & sources
- https://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf-next.git/commit/?id=93e2be344a7db169b7119de21ac1bf253b8c6907
- https://vuldb.com/?id.211363
- https://lists.debian.org/debian-lts-announce/2022/12/msg00031.htmlmailing-list
- https://lists.debian.org/debian-lts-announce/2022/12/msg00034.htmlmailing-list