{"id":"CVE-2022-2327","title":"io_uring use work_flags to determine which identity need to grab from the calling process to make sure it is consistent with the calling process when executing IORING_OP","summary":"io_uring use work_flags to determine which identity need to grab from the calling process to make sure it is consistent with the calling process when executing IORING_OP. Some operations are missing some types, which can lead to incorrec…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N","cwe":["CWE-416","CWE-415"],"vendor":"netapp","product":"h300s_firmware","affected":["h300s_firmware","h500s_firmware","h700s_firmware","h410s_firmware","h410c_firmware","linux_kernel < 5.10.125","linux_kernel >= 5.11, < 5.12"],"patched":["linux_kernel 5.12"],"published":"2022-07-22","updated":"2026-10-02","sourceUpdated":"2026-10-02T13:56:14.340","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2022-2327","references":[{"url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?h=linux-5.10.y&id=df3f3bb5059d20ef094d6b2f0256c4bf4127a859","label":"cve-coordination@google.com"},{"url":"https://kernel.dance/#df3f3bb5059d20ef094d6b2f0256c4bf4127a859","label":"cve-coordination@google.com"},{"url":"https://security.netapp.com/advisory/ntap-20230203-0009/","label":"cve-coordination@google.com"},{"url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?h=linux-5.10.y&id=df3f3bb5059d20ef094d6b2f0256c4bf4127a859","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://kernel.dance/#df3f3bb5059d20ef094d6b2f0256c4bf4127a859","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20230203-0009/","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.00273,"epssPercentile":0.17835,"ingestedAt":"2026-10-02T14:20:32.551Z","slug":"CVE-2022-2327","body":"## Overview\n\nio_uring use work_flags to determine which identity need to grab from the calling process to make sure it is consistent with the calling process when executing IORING_OP. Some operations are missing some types, which can lead to incorrect reference counts which can then lead to a double free. We recommend upgrading the kernel past commit df3f3bb5059d20ef094d6b2f0256c4bf4127a859\n\n## Affected\n\n- `h300s_firmware`\n- `h500s_firmware`\n- `h700s_firmware`\n- `h410s_firmware`\n- `h410c_firmware`\n- `linux_kernel < 5.10.125`\n- `linux_kernel >= 5.11, < 5.12`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `linux_kernel 5.12`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}