CVE-2022-1204: Use After Free

Published Apr 1, 2022
·
Updated

A use-after-free flaw was found in the Linux kernel’s Amateur Radio AX.25 protocol functionality in the way a user connects with the protocol. This flaw allows a local user to crash the system.

Other sources

There are use-after-free vulnerabilities in net/ax25/afax25.c of linux that allow attacker to crash linux kernel by simulating Amateur Radio from user-space.

Upstream fix:

https://github.com/torvalds/linux/commit/d01ffb9eee4af165d83b08dd73ebdf9fe94a519b https://github.com/torvalds/linux/commit/87563a043cef044fed5db7967a75741cc16ad2b1 https://github.com/torvalds/linux/commit/feef318c855a361a1eccd880f33e88c460eb63b4 https://github.com/torvalds/linux/commit/9fd75b66b8f68498454d685dc4ba13192ae069b0 https://github.com/torvalds/linux/commit/5352a761308397a0e6250fdc629bb3f615b94747

Red Hat

Affected Software

7 affected componentsFixes available
Linux Linux kernel<5.17
Linux Linux kernel=5.17-rc1
Linux Linux kernel=5.17-rc2
Fedoraproject Fedora=34
Fedoraproject Fedora=35
Debian Debian Linux=10.0
debian/linux
5.10.223-15.10.249-16.1.159-16.1.162-16.12.63-16.12.73-16.18.12-1

Event History

Apr 1, 2022
Data Sourced
via Red Hat·04:48 PM
DescriptionSeverityAffected Software
Aug 29, 2022
CVE Published
via MITRE·02:03 PM
Data Sourced
via MITRE·02:03 PM
DescriptionWeakness
Jan 12, 2024
Data Sourced
via Launchpad·12:04 AM
Description
Apr 28, 2025
Data Sourced
via Ubuntu·04:34 AM
RemedyDescriptionSeverityAffected Software
Feb 24, 2026
Data Sourced
via Debian·11:16 PM
DescriptionAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2022-1204?

CVE-2022-1204 has a moderate severity rating due to its potential to allow local users to crash the system.

2

How do I fix CVE-2022-1204?

To fix CVE-2022-1204, update the Linux kernel to versions 5.10.223-1, 5.10.226-1, 6.1.123-1, 6.1.119-1, 6.12.11-1, or 6.12.12-1.

3

What systems are affected by CVE-2022-1204?

CVE-2022-1204 affects various versions of the Linux kernel including versions up to 5.17 as well as specific builds of Fedora and Debian.

4

What is the nature of the vulnerability in CVE-2022-1204?

CVE-2022-1204 is a use-after-free vulnerability occurring in the Amateur Radio AX.25 protocol functionality of the Linux kernel.

5

Can CVE-2022-1204 be exploited remotely?

CVE-2022-1204 is not considered a remote vulnerability as it can only be exploited by a local user on the affected systems.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203