PT-2022-4738 · Linux+9 · Linux Kernel+9

Thadeu Lima De Souza Cascardo

·

Published

2022-08-09

·

Updated

2025-07-28

·

CVE-2022-2585

CVSS v2.0

6.8

Medium

VectorAV:L/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to a use-after-free condition when executing from a non-leader thread, where armed POSIX CPU timers are left on a list but freed. This could potentially allow an attacker to crash the system or elevate their privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2022:7318
ALSA-2022:7319
ALT-PU-2022-2569
AZL-33498
BDU:2022-05633
CVE-2022-2585
DLA-3102-1
DSA-5207-1
LSN-0089-1
MGASA-2022-0305
MGASA-2022-0308
OESA-2022-1845
OPENSUSE-SU-2022_2803-1
OPENSUSE-SU-2022_3288-1
RHSA-2022:7318
RHSA-2022:7319
RHSA-2022:7330
RHSA-2022_7318
RHSA-2022_7319
RLSA-2022:7318
RLSA-2022:7319
SUSE-SU-2022:2803-1
SUSE-SU-2022:3072-1
SUSE-SU-2022:3108-1
SUSE-SU-2022:3288-1
SUSE-SU-2025:02264-1
SUSE-SU-2025:02321-1
SUSE-SU-2025:02322-1
SUSE-SU-2025:02537-1
SUSE-SU-2025:2264-1
SUSE-SU-2025_02264-1
SUSE-SU-2025_02537-1
USN-5564-1
USN-5565-1
USN-5566-1
USN-5567-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Linuxmint
Linux Kernel
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu