PT-2022-7184 · Linux+1 · Linux Kernel+1

Marian Rehak

·

Published

2022-06-02

·

Updated

2023-02-14

·

CVE-2022-1976

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw was found in the Linux kernel's implementation of IO-URING, allowing an attacker with local executable permission to create a string of requests that can cause a use-after-free flaw within the kernel. This issue leads to memory corruption and possible privilege escalation. The flaw is related to the use of memory after it has been freed.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use After Free

Weakness Enumeration

Related Identifiers

ALT-PU-2022-2131
ALT-PU-2022-2148
AZL-10821
BDU:2023-08894
CVE-2022-1976

Affected Products

Alt Linux
Linux Kernel