Use of Uninitialized Resource The advisory has been revoked - it doesn't affect any version of package gfs2-kmp-rt  (opens in a new tab)


Threat Intelligence

EPSS
0.05% (19th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-SLES153-GFS2KMPRT-2935684
  • published25 Jun 2022
  • disclosed24 Jun 2022

Introduced: 24 Jun 2022

CVE-2022-20008  (opens in a new tab)
CWE-908  (opens in a new tab)

Amendment

The SLES security team deemed this advisory irrelevant for SLES:15.3.

NVD Description

Note: Versions mentioned in the description apply only to the upstream gfs2-kmp-rt package and not the gfs2-kmp-rt package as distributed by SLES.

In mmc_blk_read_single of block.c, there is a possible way to read kernel heap memory due to uninitialized data. This could lead to local information disclosure if reading from an SD card that triggers errors, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-216481035References: Upstream kernel

References