A memory leak problem was found in acrn_dev_ioctl in drivers/virt/acrn/hsm.c in ACRN Device Model emulates virtual NICs in VM. This flaw may allow a local privileged attacker to leak kernel unauthorized information, and may also cause a denial of service problem. #Fix Now the patch for this issue is available upstream. 1.https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=ecd1735f14d6ac868ae5d8b7a2bf193fa11f388b 2.https://lore.kernel.org/all/20220308092047.1008409-1-butterflyhuangxx@gmail.com/
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2022-1651
Hello, the CVE page https://access.redhat.com/security/cve/CVE-2022-1651 Statement paragraph says The affected code was not introduced into any kernel versions shipped with Red Hat Enterprise Linux making this vulnerable and not applicable to these platforms. Should that be "making this vulnerability not applicable" or something similar? Also, given we list all RHEL versions Not affected, why do we include that Mitigation section on that CVE page?