First published: Wed Aug 03 2022(Updated: )
A use-after-free flaw was found in route4_change in the net/sched/cls_route.c filter implementation in the Linux kernel. This flaw allows a local user to crash the system and possibly lead to a local privilege escalation problem.
Credit: security@ubuntu.com security@ubuntu.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/kernel-rt | <0:3.10.0-1160.80.1.rt56.1225.el7 | 0:3.10.0-1160.80.1.rt56.1225.el7 |
redhat/kernel | <0:3.10.0-1160.80.1.el7 | 0:3.10.0-1160.80.1.el7 |
redhat/kernel | <0:3.10.0-693.106.1.el7 | 0:3.10.0-693.106.1.el7 |
redhat/kernel | <0:3.10.0-957.99.1.el7 | 0:3.10.0-957.99.1.el7 |
redhat/kernel | <0:3.10.0-1062.76.1.el7 | 0:3.10.0-1062.76.1.el7 |
redhat/kernel-rt | <0:4.18.0-372.32.1.rt7.189.el8_6 | 0:4.18.0-372.32.1.rt7.189.el8_6 |
redhat/kernel | <0:4.18.0-372.32.1.el8_6 | 0:4.18.0-372.32.1.el8_6 |
redhat/kernel | <0:4.18.0-147.76.1.el8_1 | 0:4.18.0-147.76.1.el8_1 |
redhat/kernel | <0:4.18.0-193.93.1.el8_2 | 0:4.18.0-193.93.1.el8_2 |
redhat/kernel-rt | <0:4.18.0-193.93.1.rt13.143.el8_2 | 0:4.18.0-193.93.1.rt13.143.el8_2 |
redhat/kernel-rt | <0:4.18.0-305.65.1.rt7.137.el8_4 | 0:4.18.0-305.65.1.rt7.137.el8_4 |
redhat/kernel | <0:4.18.0-305.65.1.el8_4 | 0:4.18.0-305.65.1.el8_4 |
redhat/kernel | <3.10 | 3.10 |
Linux Kernel | <4.9.326 | |
Linux Kernel | >=4.10<4.14.291 | |
Linux Kernel | >=4.15<4.19.256 | |
Linux Kernel | >=4.20<5.4.211 | |
Linux Kernel | >=5.5<5.10.137 | |
Linux Kernel | >=5.11<5.15.61 | |
Linux Kernel | >=5.16<5.18.18 | |
Linux Kernel | >=5.19<5.19.2 | |
Ubuntu Linux | =14.04 | |
Ubuntu Linux | =16.04 | |
Ubuntu Linux | =18.04 | |
Ubuntu Linux | =20.04 | |
Ubuntu Linux | =22.04 | |
Linux kernel | ||
debian/linux | 5.10.223-1 5.10.226-1 6.1.123-1 6.1.119-1 6.12.11-1 6.12.12-1 |
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2022-2588 has a high severity rating due to its potential for local privilege escalation and system crashes.
To fix CVE-2022-2588, update the Linux kernel to a patched version, such as those specified in the vulnerability details.
CVE-2022-2588 affects multiple versions of the Linux kernel prior to the fixed versions outlined in the release notes.
CVE-2022-2588 is classified as a use-after-free vulnerability found in the cls_route filter implementation.
CVE-2022-2588 is not remotely exploitable; it requires local user access to the system for exploitation.