CVE-2022-1652: Use After Free
Last updated 10 September 2026
Other sources
Linux Kernel could allow a local attacker to execute arbitrary code on the system, caused by a concurrency use-after-free flaw in the badflpintr function. By executing a specially-crafted program, an attacker could exploit this vulnerability to execute arbitrary code or cause a denial of service condition on the system.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.176-1Fixed in 6.1.187-1Fixed in 6.12.107-1Fixed in 7.1.13-1
Event History
Frequently Asked Questions
What is the severity of CVE-2022-1652?
CVE-2022-1652 has a high severity rating due to its potential to allow local attackers to execute arbitrary code.
How do I fix CVE-2022-1652?
To address CVE-2022-1652, ensure that you upgrade to a patched version of the Linux Kernel, such as 5.10.223-1 or newer.
What systems are affected by CVE-2022-1652?
CVE-2022-1652 affects multiple versions of Linux Kernel ranging from 2.6.12 up to 5.17.10.
Who can exploit CVE-2022-1652?
CVE-2022-1652 can be exploited by local attackers who can run specially-crafted programs on the vulnerable system.
What type of vulnerability is CVE-2022-1652?
CVE-2022-1652 is a concurrency use-after-free vulnerability found in the bad_flp_intr function of the Linux Kernel.