First published: Wed May 18 2022(Updated: )
A use-after-free flaw was found in the Linux kernel’s io_uring subsystem in the way a user sets up a ring with IORING_SETUP_IOPOLL with more than one task completing submissions on this ring. This flaw allows a local user to crash or escalate their privileges on the system.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/linux | 4.19.249-2 4.19.289-2 5.10.197-1 5.10.191-1 6.1.66-1 6.1.69-1 6.5.13-1 6.6.8-1 | |
Google Android | ||
Linux Linux kernel | >=5.10<5.12 | |
Netapp H410c Firmware | ||
Netapp H410c | ||
Netapp H300s Firmware | ||
Netapp H300s | ||
Netapp H500s Firmware | ||
Netapp H500s | ||
Netapp H700s Firmware | ||
Netapp H700s | ||
Netapp H410s Firmware | ||
Netapp H410s |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-1786.
CVE-2022-1786 has a severity value of 7, which is considered high.
CVE-2022-1786 affects the Linux kernel (versions between 5.10 and 5.12) and Netapp H410c Firmware.
CVE-2022-1786 allows a local user to crash or escalate their privileges on the system.
Yes, fixes are available. Please refer to the references for more information on how to apply the fixes.