PT-2022-1363 · Linux+5 · Linux Kernel+5
Published
2022-01-03
·
Updated
2024-06-15
·
CVE-2022-24958
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions through 5.16.8
Description
The issue is related to the mishandling of dev->buf release in the drivers/usb/gadget/legacy/inode.c component of the Linux kernel. This can lead to a use-after-free condition, potentially allowing an attacker to cause a denial of service or execute arbitrary code, resulting in local escalation of privilege without needing additional execution privileges. User interaction is not required for exploitation.
Recommendations
For Linux kernel versions through 5.16.8, update to a version later than 5.16.8 to resolve the issue.
As a temporary workaround, consider restricting access to the vulnerable
inode.c component until a patch is available.Fix
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Linuxmint
Linux Kernel
Suse
Ubuntu