CVE Vulnerabilities

CVE-2022-3707

Double Free

Published: Mar 06, 2023 | Modified: Nov 07, 2023
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A double-free memory flaw was found in the Linux kernel. The Intel GVT-g graphics driver triggers VGA card system resource overload, causing a fail in the intel_gvt_dma_map_guest_page function. This issue could allow a local user to crash the system.

Weakness

The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations.

Affected Software

Name Vendor Start Version End Version
Linux_kernel Linux * 6.1 (excluding)
Linux_kernel Linux 6.1 (including) 6.1 (including)
Linux_kernel Linux 6.1-rc1 (including) 6.1-rc1 (including)
Linux_kernel Linux 6.1-rc2 (including) 6.1-rc2 (including)

Potential Mitigations

References