PT-2022-3183 · Linux+4 · Linux Kernel+4

Mathias Krause

·

Published

2022-01-27

·

Updated

2023-08-14

·

CVE-2022-1998

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to a use after free flaw in the Linux kernel's File System notify functionality, specifically in the way the copy info records to user() function is called, which can fail in copy event to user(). This can be exploited by a local user to potentially escalate their privileges or crash the system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2022:7933
ALSA-2022:8267
ALT-PU-2022-1221
ALT-PU-2022-1223
ALT-PU-2022-1239
ALT-PU-2022-1289
ALT-PU-2022-1297
ALT-PU-2022-1298
ALT-PU-2022-1300
ALT-PU-2022-1419
ALT-PU-2022-1421
ALT-PU-2022-1428
ALT-PU-2022-1432
ALT-PU-2022-1441
ALT-PU-2022-1467
ALT-PU-2022-1540
ALT-PU-2022-2145
ALT-PU-2023-4894
AZL-9917
BDU:2022-03863
CVE-2022-1998
OESA-2022-1660
OPENSUSE-SU-2022_2520-1
OPENSUSE-SU-2022_2615-1
RHSA-2022:7933
RHSA-2022:8267
RHSA-2022_7933
RHSA-2022_8267
SUSE-SU-2022:2520-1
SUSE-SU-2022:2615-1

Affected Products

Alt Linux
Almalinux
Linux Kernel
Red Hat
Suse