First published: Fri Apr 01 2022(Updated: )
A use-after-free vulnerability was found in drm_lease_held in drivers/gpu/drm/drm_lease.c in the Linux kernel due to a race problem. This flaw allows a local user privilege attacker to cause a denial of service (DoS) or a kernel information leak.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/kernel | <0:4.18.0-425.3.1.el8 | 0:4.18.0-425.3.1.el8 |
redhat/kernel | <0:5.14.0-162.6.1.el9_1 | 0:5.14.0-162.6.1.el9_1 |
redhat/kernel-rt | <0:5.14.0-162.6.1.rt21.168.el9_1 | 0:5.14.0-162.6.1.rt21.168.el9_1 |
redhat/Linux kernel | <5.15 | 5.15 |
Linux Kernel | >=5.17<=5.17.4 | |
Red Hat Enterprise Linux | =8.0 |
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2022-1280 has a severity rating of medium due to its potential for denial of service and kernel information leak.
To fix CVE-2022-1280, update the Linux kernel to one of the remedied versions specified, such as 0:4.18.0-425.3.1.el8 or 0:5.14.0-162.6.1.el9_1.
The CVE-2022-1280 vulnerability is caused by a use-after-free flaw resulting from a race condition in the drm_lease_held function.
CVE-2022-1280 can only be exploited by a local user, indicating it does not present a remote attack vector.
CVE-2022-1280 affects various versions of the Linux kernel, specifically those before the patched versions provided by Red Hat.