CVE-2022-4269

A flaw was found in the Linux kernel Traffic Control (TC) subsystem. Using a specific networking configuration (redirecting egress packets to ingress using TC action "mirred") a local unprivileged user could trigger a CPU soft lockup (ABBA deadlock) when the transport protocol in use (TCP or SCTP) does a retransmission, resulting in a denial of service condition.
Configurations

Configuration 1 (hide)

cpe:2.3:o:linux:linux_kernel:4.1:rc1:*:*:*:*:*:*

History

21 Nov 2024, 07:34

Type Values Removed Values Added
Summary
  • (es) Se encontró un fallo en el subsistema de control de tráfico (TC) del kernel de Linux. Usando una configuración de red específica (redireccionando paquetes de salida para ingresar usando la acción TC "mirred"), un usuario local sin privilegios podría desencadenar un bloqueo suave de la CPU (bloqueo ABBA) cuando el protocolo de transporte en uso (TCP o SCTP) realiza una retransmisión, lo que resulta en una condición de denegación de servicio.
References () https://lists.debian.org/debian-lts-announce/2023/10/msg00027.html - () https://lists.debian.org/debian-lts-announce/2023/10/msg00027.html -
References () https://lore.kernel.org/netdev/33dc43f587ec1388ba456b4915c75f02a8aae226.1663945716.git.dcaratti%40redhat.com/ - () https://lore.kernel.org/netdev/33dc43f587ec1388ba456b4915c75f02a8aae226.1663945716.git.dcaratti%40redhat.com/ -
References () https://security.netapp.com/advisory/ntap-20230929-0001/ - () https://security.netapp.com/advisory/ntap-20230929-0001/ -
References () https://www.debian.org/security/2023/dsa-5480 - () https://www.debian.org/security/2023/dsa-5480 -

Information

Published : 2022-12-05 16:15

Updated : 2025-04-14 18:15


NVD link : CVE-2022-4269

Mitre link : CVE-2022-4269

CVE.ORG link : CVE-2022-4269


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-833

Deadlock