CVE-2022-29581: Use After Free
A use-after-free flaw was found in u32change in net/sched/clsu32.c in the network subcomponent of the Linux kernel. This flaw could allow a local attacker to crash the system and cause a privilege escalation, and a kernel information leak problem.
References and upstream patch: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=3db09e762dc79584a69c10d74a6b98f89a9979f8 https://kernel.dance/#3db09e762dc79584a69c10d74a6b98f89a9979f8
Other sources
A use-after-free flaw was found in u32change in net/sched/clsu32.c in the network subcomponent of the Linux kernel. This flaw allows a local attacker to crash the system, cause a privilege escalation, and leak kernel information.
Improper Update of Reference Count vulnerability in net/sched of Linux Kernel allows local attacker to cause privilege escalation to root. This issue affects: Linux Kernel versions prior to 5.18; version 4.14 and later versions.
Affected Software
Remediation
Information
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2022-29581?
CVE-2022-29581 is considered high severity due to its potential for local privilege escalation and system crashes.
How do I fix CVE-2022-29581?
To remediate CVE-2022-29581, upgrade to a fixed version of the Linux kernel according to the available patches for your distribution.
Which systems are affected by CVE-2022-29581?
CVE-2022-29581 affects various Linux kernel versions across different distributions including Red Hat, Debian, and Ubuntu.
What happens if CVE-2022-29581 is exploited?
Exploitation of CVE-2022-29581 could lead to a local attacker gaining elevated privileges and causing a system crash.
Is there a patch available for CVE-2022-29581?
Yes, patches for CVE-2022-29581 are provided in kernel updates by affected Linux distributions.