Bugzilla – Bug 1203801
VUL-0: CVE-2022-3103: kernel-source: io_uring: off-by-one in sync cancelation file check
Last modified: 2022-09-28 07:17:10 UTC
rh#2130189 off-by-one in io_uring module. References: https://bugzilla.redhat.com/show_bug.cgi?id=2130189 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-3103 https://www.cve.org/CVERecord?id=CVE-2022-3103 https://github.com/torvalds/linux/releases/tag/v6.0-rc3
The vulnerability was introduced by [0] and fixed by [1]. Both commits are part of the 6.0 kernel and weren't merged in any of our branches, so I'd say we aren't affected. Please confirm. [0] https://github.com/torvalds/linux/commit/78a861b9495920f8609dee5b670dacbff09d359f [1] https://github.com/torvalds/linux/commit/47abea041f897d64dbd5777f0cf7745148f85d75
(In reply to Gabriele Sonnu from comment #1) > The vulnerability was introduced by [0] and fixed by [1]. Both commits are > part of the 6.0 kernel and weren't merged in any of our branches, so I'd say > we aren't affected. Please confirm. Yes, none of our branches are affected.
Back to the sec team
Doesn't affect us, closing.