Skip to content

kernel CVE-2022-40768

Moderate
rpkelly published GHSA-jw9m-fq9g-prgw Jan 27, 2023

Package

kernel-5.10 (bottlerocket)

Affected versions

< 1.12.0

Patched versions

1.12.0
kernel-5.15 (bottlerocket)
< 1.12.0
1.12.0

Description

drivers/scsi/stex.c in the Linux kernel through 5.19.9 allows local users to obtain sensitive information from kernel memory because stex_queuecommand_lck lacks a memset for the PASSTHRU_CMD case.

Severity

Moderate

CVE ID

CVE-2022-40768

Weaknesses

No CWEs