PT-2022-7362 · Linux+1 · Linux Kernel+1

Rohit Keshri

·

Published

2022-08-30

·

Updated

2026-04-20

·

CVE-2022-1247

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions linux-kernel (affected versions not specified)
Description The issue is related to a race condition in the rose connect() function. It affects the rose driver, which utilizes rose neigh->use to track the number of objects using rose neigh. When attempting to delete a rose route via rose ioctl(), the driver calls rose del node() and removes neighbors only if their count and use are zero. This vulnerability may allow an attacker to impact the confidentiality, integrity, and availability of protected information due to synchronization errors when using shared resources.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Race Condition

Weakness Enumeration

Related Identifiers

BDU:2024-04163
CVE-2022-1247
ECHO-C511-3DB7-1CC7

Affected Products

Debian
Linux Kernel