PT-2022-6249 · Linux+4 · Linux Kernel+4
Hyunwoo Kim
·
Published
2022-11-15
·
Updated
2026-05-26
·
CVE-2022-45885
CVSS v3.1
7.0
High
| Vector | AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 6.0.9
Description
The issue is related to a race condition in the Linux kernel's DVB driver, specifically in the
dvb frontend.c file. This condition can cause a use-after-free error when a device is disconnected, potentially allowing an attacker to cause a denial of service or elevate their privileges. The estimated number of potentially affected devices is not provided.Recommendations
For Linux kernel versions prior to 6.0.9, update to a version 6.0.9 or later to resolve the issue.
As a temporary workaround, consider restricting access to the
dvb frontend.c driver to minimize the risk of exploitation.Exploit
Fix
DoS
Race Condition
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Debian
Linux Kernel
Red Os
Suse