PT-2022-1363 · Linux+5 · Linux Kernel+5

Published

2022-01-03

·

Updated

2024-06-15

·

CVE-2022-24958

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions through 5.16.8
Description The issue is related to the mishandling of dev->buf release in the drivers/usb/gadget/legacy/inode.c component of the Linux kernel. This can lead to a use-after-free condition, potentially allowing an attacker to cause a denial of service or execute arbitrary code, resulting in local escalation of privilege without needing additional execution privileges. User interaction is not required for exploitation.
Recommendations For Linux kernel versions through 5.16.8, update to a version later than 5.16.8 to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable inode.c component until a patch is available.

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-1228
ALT-PU-2022-1239
ALT-PU-2022-1647
ALT-PU-2022-2155
ALT-PU-2023-1684
ALT-PU-2023-1741
ALT-PU-2023-1814
ALT-PU-2023-4894
ASB-A-220261709
AZL-8525
BDU:2022-00823
CVE-2022-24958
DLA-3065-1
OESA-2022-1539
OPENSUSE-SU-2022:1037-1
OPENSUSE-SU-2022:1039-1
OPENSUSE-SU-2022_1037-1
OPENSUSE-SU-2022_1039-1
OPENSUSE-SU-2024:11857-1
OPENSUSE-SU-2024:13704-1
SUSE-SU-2022:0759-1
SUSE-SU-2022:1037-1
SUSE-SU-2022:1038-1
SUSE-SU-2022:1039-1
SUSE-SU-2022:1257-1
USN-5381-1
USN-5418-1
USN-5467-1
USN-5468-1
USN-5505-1
USN-5513-1

Affected Products

Alt Linux
Astra Linux
Linuxmint
Linux Kernel
Suse
Ubuntu