CVE-2022-1652: Use After Free

Published May 31, 2022
·
Updated

Last updated 10 September 2026

Other sources

Linux Kernel could allow a local attacker to execute arbitrary code on the system, caused by a concurrency use-after-free flaw in the badflpintr function. By executing a specially-crafted program, an attacker could exploit this vulnerability to execute arbitrary code or cause a denial of service condition on the system.

Launchpad

Affected Software

30 affected componentsFixes available
Linux Linux kernel>=2.6.12<4.9.316
Linux Linux kernel>=4.10<4.14.281
Linux Linux kernel>=4.15<4.19.245
Linux Linux kernel>=4.20<5.4.196
Linux Linux kernel>=5.5<5.10.118
Linux Linux kernel>=5.11<5.15.42
Linux Linux kernel>=5.16<5.17.10
redhat Enterprise Linux=9.0
Debian Debian Linux=10.0
NetApp H410c Firmware
NetApp H410c
NetApp H300s Firmware
NetApp H300s
NetApp H500s Firmware
NetApp H500s
NetApp H700s Firmware
NetApp H700s
NetApp H410s Firmware
NetApp H410s
All of the following
NetApp H410c Firmware
NetApp H410c
All of the following
NetApp H300s Firmware
NetApp H300s
All of the following
NetApp H500s Firmware
NetApp H500s
All of the following
NetApp H700s Firmware
NetApp H700s
All of the following
NetApp H410s Firmware
NetApp H410s
debian/linux
6.1.176-16.1.187-16.12.107-17.1.13-1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade debian/linux to a version that resolves this vulnerability.

    Fixed in 6.1.176-1Fixed in 6.1.187-1Fixed in 6.12.107-1Fixed in 7.1.13-1

Event History

May 31, 2022
CVE Published
via MITRE·06:05 PM
Data Sourced
via MITRE·06:05 PM
DescriptionWeakness
Jun 2, 2022
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Jan 12, 2024
Data Sourced
via Launchpad·12:04 AM
Description
Sep 10, 2026
Data Sourced
via Ubuntu·01:07 PM
RemedyDescriptionSeverityAffected Software
Sep 12, 2026
Data Sourced
via Debian·01:09 PM
DescriptionAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2022-1652?

CVE-2022-1652 has a high severity rating due to its potential to allow local attackers to execute arbitrary code.

2

How do I fix CVE-2022-1652?

To address CVE-2022-1652, ensure that you upgrade to a patched version of the Linux Kernel, such as 5.10.223-1 or newer.

3

What systems are affected by CVE-2022-1652?

CVE-2022-1652 affects multiple versions of Linux Kernel ranging from 2.6.12 up to 5.17.10.

4

Who can exploit CVE-2022-1652?

CVE-2022-1652 can be exploited by local attackers who can run specially-crafted programs on the vulnerable system.

5

What type of vulnerability is CVE-2022-1652?

CVE-2022-1652 is a concurrency use-after-free vulnerability found in the bad_flp_intr function of the Linux Kernel.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203