drivers/scsi/stex.c in the Linux kernel through 5.19.9 allows local users to obtain sensitive information from kernel memory because stexqueuecommandlck lacks a memset for the PASSTHRU_CMD case.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-40768.json"
[
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"line_hashes": [
"284800229218217135867924790033236827863",
"125961204795419930876895183533007746244",
"20678598626312921378712765638186665070",
"142683567666484297404263183273256743192",
"77006857625652926319722920295611402740",
"52925962061377303314098693527040018078",
"20383316183921489648211871152515215366",
"47277403370303323122167745034406668598",
"102651008448784733090638457604760866835",
"238349340125937856840727163249203794364",
"268996312263230995247030982822472265291",
"6368577009191417774246289124996530038"
],
"threshold": 0.9
},
"signature_type": "Line",
"id": "CVE-2022-40768-2044bd20",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@6022f210461fef67e6e676fd8544ca02d1bcfa7a",
"target": {
"file": "drivers/scsi/stex.c"
}
},
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"length": 2976.0,
"function_hash": "10540814384308164410380911590465785255"
},
"signature_type": "Function",
"id": "CVE-2022-40768-4371eeb6",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@6022f210461fef67e6e676fd8544ca02d1bcfa7a",
"target": {
"function": "stex_queuecommand_lck",
"file": "drivers/scsi/stex.c"
}
},
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"line_hashes": [
"166261581907547118501146473837936217554",
"81405467002086924550584351339422410048",
"243962287770625603903916900444331569306",
"84211666979780620353449231346304808448"
],
"threshold": 0.9
},
"signature_type": "Line",
"id": "CVE-2022-40768-b40e344b",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@6022f210461fef67e6e676fd8544ca02d1bcfa7a",
"target": {
"file": "include/scsi/scsi_cmnd.h"
}
}
]