cve-2022-23090
Vulnerability from cvelistv5
Published
2024-02-15 05:09
Modified
2025-03-28 23:57
Severity ?
EPSS score ?
Summary
AIO credential reference count leak
References
{ "containers": { "adp": [ { "providerMetadata": { "dateUpdated": "2024-08-03T03:28:43.512Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "vendor-advisory", "x_transferred" ], "url": "https://security.freebsd.org/advisories/FreeBSD-SA-22:10.aio.asc" }, { "tags": [ "x_transferred" ], "url": "https://security.netapp.com/advisory/ntap-20240415-0007/" } ], "title": "CVE Program Container" }, { "affected": [ { "cpes": [ "cpe:2.3:o:freebsd:freebsd:*:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "product": "freebsd", "vendor": "freebsd", "versions": [ { "lessThan": "13.0_p12", "status": "affected", "version": "13.0", "versionType": "custom" }, { "lessThan": "13.1_p1", "status": "affected", "version": "13.1", "versionType": "custom" } ] } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "NONE", "baseScore": 7.7, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N", "version": "3.1" } }, { "other": { "content": { "id": "CVE-2022-23090", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2024-02-21T17:10:00.368345Z", "version": "2.0.3" }, "type": "ssvc" } } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-416", "description": "CWE-416 Use After Free", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-03-28T23:57:52.965Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" } ], "cna": { "affected": [ { "defaultStatus": "unknown", "modules": [ "kernel" ], "product": "FreeBSD", "vendor": "FreeBSD", "versions": [ { "lessThan": "p1", "status": "affected", "version": "13.1-RELEASE", "versionType": "release" }, { "lessThan": "p12", "status": "affected", "version": "13.0-RELEASE", "versionType": "release" }, { "lessThan": "p6", "status": "affected", "version": "12.3-RELEASE", "versionType": "release" } ] } ], "credits": [ { "lang": "en", "type": "finder", "user": "00000000-0000-4000-9000-000000000000", "value": "Chris J-D \u003cchris@accessvector.net\u003e" } ], "datePublic": "2022-08-09T23:00:00.000Z", "descriptions": [ { "lang": "en", "value": "The aio_aqueue function, used by the lio_listio system call, fails to release a reference to a credential in an error case.\n\nAn attacker may cause the reference count to overflow, leading to a use after free (UAF)." } ], "providerMetadata": { "dateUpdated": "2024-04-15T15:06:15.094Z", "orgId": "63664ac6-956c-4cba-a5d0-f46076e16109", "shortName": "freebsd" }, "references": [ { "tags": [ "vendor-advisory" ], "url": "https://security.freebsd.org/advisories/FreeBSD-SA-22:10.aio.asc" }, { "url": "https://security.netapp.com/advisory/ntap-20240415-0007/" } ], "source": { "discovery": "UNKNOWN" }, "title": "AIO credential reference count leak", "x_generator": { "engine": "Vulnogram 0.1.0-dev" } } }, "cveMetadata": { "assignerOrgId": "63664ac6-956c-4cba-a5d0-f46076e16109", "assignerShortName": "freebsd", "cveId": "CVE-2022-23090", "datePublished": "2024-02-15T05:09:27.389Z", "dateReserved": "2022-01-10T22:07:46.041Z", "dateUpdated": "2025-03-28T23:57:52.965Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1", "meta": { "nvd": "{\"cve\":{\"id\":\"CVE-2022-23090\",\"sourceIdentifier\":\"secteam@freebsd.org\",\"published\":\"2024-02-15T06:15:45.103\",\"lastModified\":\"2025-06-04T21:59:04.990\",\"vulnStatus\":\"Analyzed\",\"cveTags\":[],\"descriptions\":[{\"lang\":\"en\",\"value\":\"The aio_aqueue function, used by the lio_listio system call, fails to release a reference to a credential in an error case.\\n\\nAn attacker may cause the reference count to overflow, leading to a use after free (UAF).\"},{\"lang\":\"es\",\"value\":\"La funci\u00f3n aio_aqueue, utilizada por la llamada al sistema lio_listio, no puede liberar una referencia a una credencial en un caso de error. Un atacante puede provocar que el recuento de referencias se desborde, lo que provocar\u00e1 un use after free (UAF).\"}],\"metrics\":{\"cvssMetricV31\":[{\"source\":\"134c704f-9b21-4f2e-91b3-4a467353bcc0\",\"type\":\"Secondary\",\"cvssData\":{\"version\":\"3.1\",\"vectorString\":\"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N\",\"baseScore\":7.7,\"baseSeverity\":\"HIGH\",\"attackVector\":\"LOCAL\",\"attackComplexity\":\"LOW\",\"privilegesRequired\":\"NONE\",\"userInteraction\":\"NONE\",\"scope\":\"UNCHANGED\",\"confidentialityImpact\":\"HIGH\",\"integrityImpact\":\"HIGH\",\"availabilityImpact\":\"NONE\"},\"exploitabilityScore\":2.5,\"impactScore\":5.2}]},\"weaknesses\":[{\"source\":\"134c704f-9b21-4f2e-91b3-4a467353bcc0\",\"type\":\"Secondary\",\"description\":[{\"lang\":\"en\",\"value\":\"CWE-416\"}]}],\"configurations\":[{\"nodes\":[{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:freebsd:freebsd:12.3:beta1:*:*:*:*:*:*\",\"matchCriteriaId\":\"E231B24D-5CA9-4107-A819-57EE116AD644\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:freebsd:freebsd:12.3:p1:*:*:*:*:*:*\",\"matchCriteriaId\":\"3B6DCD8A-331E-419F-9253-C4D35C1DF54B\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:freebsd:freebsd:12.3:p2:*:*:*:*:*:*\",\"matchCriteriaId\":\"4578E06C-16C6-435E-9E51-91CB02602355\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:freebsd:freebsd:12.3:p3:*:*:*:*:*:*\",\"matchCriteriaId\":\"71FA1F6C-7E53-40F8-B9E1-5FD28D5DAADA\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:freebsd:freebsd:12.3:p4:*:*:*:*:*:*\",\"matchCriteriaId\":\"0EC87BCE-17F0-479B-84DC-516C24FBD396\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:freebsd:freebsd:12.3:p5:*:*:*:*:*:*\",\"matchCriteriaId\":\"620C23ED-400C-438C-8427-94437F12EDAF\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:freebsd:freebsd:13.0:beta1:*:*:*:*:*:*\",\"matchCriteriaId\":\"7412DBD8-BB1F-48A8-AAE1-BA5C8D7BDDF7\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:freebsd:freebsd:13.0:beta2:*:*:*:*:*:*\",\"matchCriteriaId\":\"833DFF5B-BC50-424A-ABCF-EC632F421B76\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:freebsd:freebsd:13.0:beta3:*:*:*:*:*:*\",\"matchCriteriaId\":\"9F27016E-4117-4094-BB7A-9C56E38024D9\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:freebsd:freebsd:13.0:beta3-p1:*:*:*:*:*:*\",\"matchCriteriaId\":\"EC7326E3-908D-47A1-B848-3AA7F34B3DD3\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:freebsd:freebsd:13.0:beta4:*:*:*:*:*:*\",\"matchCriteriaId\":\"B149BF69-951D-47B4-996C-9E4773DA75B7\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:freebsd:freebsd:13.0:p1:*:*:*:*:*:*\",\"matchCriteriaId\":\"04A0E266-714C-4753-A652-A51F25582C78\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:freebsd:freebsd:13.0:p10:*:*:*:*:*:*\",\"matchCriteriaId\":\"D133E8E0-4E88-451C-9693-5DE5C3092AD2\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:freebsd:freebsd:13.0:p11:*:*:*:*:*:*\",\"matchCriteriaId\":\"FF1A096F-EC60-4C7D-AE40-D1DDAC9D4E40\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:freebsd:freebsd:13.0:p2:*:*:*:*:*:*\",\"matchCriteriaId\":\"556111A1-C236-4DF6-9438-F9C874451A58\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:freebsd:freebsd:13.0:p3:*:*:*:*:*:*\",\"matchCriteriaId\":\"1673F16B-463A-492C-B66F-48917008F7F5\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:freebsd:freebsd:13.0:p4:*:*:*:*:*:*\",\"matchCriteriaId\":\"E73B211F-2CA9-47A4-B318-F24CC1C7E589\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:freebsd:freebsd:13.0:p5:*:*:*:*:*:*\",\"matchCriteriaId\":\"7C13DDEF-FF5F-4723-9C25-4EA66AE2CEDD\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:freebsd:freebsd:13.0:p6:*:*:*:*:*:*\",\"matchCriteriaId\":\"7A942EA9-0DD3-44BC-B582-C680BA34E88F\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:freebsd:freebsd:13.0:p7:*:*:*:*:*:*\",\"matchCriteriaId\":\"689BC10B-0404-4468-B604-9D96337F9BD1\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:freebsd:freebsd:13.0:p8:*:*:*:*:*:*\",\"matchCriteriaId\":\"38DDAA43-3E9C-479F-8416-E3B9BE23C31B\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:freebsd:freebsd:13.0:p9:*:*:*:*:*:*\",\"matchCriteriaId\":\"AE490480-1EA1-4684-A643-9749E87A8448\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:freebsd:freebsd:13.0:rc1:*:*:*:*:*:*\",\"matchCriteriaId\":\"FC271C93-EB83-4301-B7BA-F3249B71B1EA\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:freebsd:freebsd:13.0:rc2:*:*:*:*:*:*\",\"matchCriteriaId\":\"04329338-AC28-4A74-BE6B-CE8EC6CC37B7\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:freebsd:freebsd:13.0:rc3:*:*:*:*:*:*\",\"matchCriteriaId\":\"ADBA841F-5C83-4759-84B7-B59DA1B12EA8\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:freebsd:freebsd:13.0:rc4:*:*:*:*:*:*\",\"matchCriteriaId\":\"6A8F38B3-A6DA-4178-A2BD-0D4F0267C384\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:freebsd:freebsd:13.0:rc5:*:*:*:*:*:*\",\"matchCriteriaId\":\"9BB028A0-70F6-42DA-9E5A-F7AAF74ED45B\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:o:freebsd:freebsd:13.0:rc5-p1:*:*:*:*:*:*\",\"matchCriteriaId\":\"00D28E4E-022B-482E-9952-7F7F47C427C2\"}]}]}],\"references\":[{\"url\":\"https://security.freebsd.org/advisories/FreeBSD-SA-22:10.aio.asc\",\"source\":\"secteam@freebsd.org\",\"tags\":[\"Vendor Advisory\"]},{\"url\":\"https://security.netapp.com/advisory/ntap-20240415-0007/\",\"source\":\"secteam@freebsd.org\",\"tags\":[\"Third Party Advisory\"]},{\"url\":\"https://security.freebsd.org/advisories/FreeBSD-SA-22:10.aio.asc\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Vendor Advisory\"]},{\"url\":\"https://security.netapp.com/advisory/ntap-20240415-0007/\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Third Party Advisory\"]}]}}" } }
Loading...
Loading...
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.