First published: Fri Apr 01 2022(Updated: )
A use-after-free flaw was found in the Linux kernel’s Amateur Radio AX.25 protocol functionality in the way a user connects with the protocol. This flaw allows a local user to crash the system.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Kernel | <5.17 | |
Linux Kernel | =5.17-rc1 | |
Linux Kernel | =5.17-rc2 | |
Fedoraproject Fedora | =34 | |
Fedoraproject Fedora | =35 | |
Debian Debian Linux | =10.0 | |
debian/linux | 5.10.223-1 5.10.226-1 6.1.123-1 6.1.119-1 6.12.11-1 6.12.12-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-1204 has a moderate severity rating due to its potential to allow local users to crash the system.
To fix CVE-2022-1204, update the Linux kernel to versions 5.10.223-1, 5.10.226-1, 6.1.123-1, 6.1.119-1, 6.12.11-1, or 6.12.12-1.
CVE-2022-1204 affects various versions of the Linux kernel including versions up to 5.17 as well as specific builds of Fedora and Debian.
CVE-2022-1204 is a use-after-free vulnerability occurring in the Amateur Radio AX.25 protocol functionality of the Linux kernel.
CVE-2022-1204 is not considered a remote vulnerability as it can only be exploited by a local user on the affected systems.