An issue was discovered in the Linux kernel through 5.19.8. drivers/firmware/efi/capsule-loader.c has a race condition with a resultant use-after-free.
[
{
"id": "CVE-2022-40307-43ccc85b",
"deprecated": false,
"signature_type": "Function",
"digest": {
"function_hash": "153204234574112632517498414549660053243",
"length": 231.0
},
"signature_version": "v1",
"target": {
"function": "efi_capsule_release",
"file": "drivers/firmware/efi/capsule-loader.c"
},
"source": "https://github.com/torvalds/linux/commit/9cb636b5f6a8cc6d1b50809ec8f8d33ae0c84c95"
},
{
"id": "CVE-2022-40307-b5cfe9ff",
"deprecated": false,
"signature_type": "Function",
"digest": {
"function_hash": "72434197523419643521541518719629736468",
"length": 238.0
},
"signature_version": "v1",
"target": {
"function": "efi_capsule_flush",
"file": "drivers/firmware/efi/capsule-loader.c"
},
"source": "https://github.com/torvalds/linux/commit/9cb636b5f6a8cc6d1b50809ec8f8d33ae0c84c95"
},
{
"id": "CVE-2022-40307-e2a2fc09",
"deprecated": false,
"signature_type": "Line",
"digest": {
"line_hashes": [
"76862463562391422572182397049924122837",
"56505975990877697631806806895021551559",
"253226488319370203991627409346826643351",
"283625047166841068887662813313580304177",
"265627572611879885872908341036274560579",
"136616705561780524415946304362977076765",
"228304377292732380297006724395381257208",
"193440465396174028464622712611313061588",
"159007939012149164678184403650106008887",
"293465920652495675621591122513998692463",
"306747624769363325587242159799083134183",
"144048894469398437735802262259038412937",
"287357158431643854731426794039890583886",
"311036144720739914750433638490367696010",
"289975469632314177890862713687604366969",
"104611422386415140153949603955924197940",
"242576605761490282745120986345196178538",
"84813625506590870180335395547602342404",
"176193426712465960992053673485083484481",
"50115559439191114203184181331864450001",
"212882520336892315320064928238787710601"
],
"threshold": 0.9
},
"signature_version": "v1",
"target": {
"file": "drivers/firmware/efi/capsule-loader.c"
},
"source": "https://github.com/torvalds/linux/commit/9cb636b5f6a8cc6d1b50809ec8f8d33ae0c84c95"
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-40307.json"