CVE-2022-29582

Updated on 22 Apr 2022

Severity

7.0 High severity

Details

CVSS score
7.0
CVSS vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Overview

About vulnerability

In the Linux kernel before 5.17.3, fs/io_uring.c has a use-after-free due to a race condition in io_uring timeouts. This can be triggered by a local user who has no access to any user namespace; however, the race condition perhaps can only be exploited infrequently.

Details

Fixes

KernelCare state

Live-patch status from KernelCare for each operating system.

Operating system Status Covered kernels
Amazon Linux 2023 Will Not Fix
Amazon Linux 2 5.10 Will Not Fix
Amazon Linux 2 5.15 Will Not Fix
Debian 11 Released
8 kernels
  • 5.10.84-1
  • 5.10.46-4
  • 5.10.70-1
  • 5.10.92-1
  • 5.10.46-5
  • 5.10.106-1
  • 5.10.103-1
  • 5.10.92-2