CVE-2022-29582: Use After Free
In the Linux kernel before 5.17.3, fs/iouring.c has a use-after-free due to a race condition in iouring timeouts. This can be triggered by a local user who has no access to any user namespace; however, the race condition perhaps can only be exploited infrequently.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 4.19.249-2Fixed in 4.19.289-2Fixed in 5.10.197-1Fixed in 5.10.205-2Fixed in 6.1.66-1Fixed in 6.1.69-1Fixed in 6.5.13-1Fixed in 6.6.9-1
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-29582.
What is the severity of CVE-2022-29582?
The severity of CVE-2022-29582 is high (severity value: 7).
Which software is affected by CVE-2022-29582?
Linux kernel versions before 5.17.3, Debian Linux 11.0, and Google Android are affected by CVE-2022-29582.
How can CVE-2022-29582 be exploited?
CVE-2022-29582 can be triggered by a local user who has no access to any user namespace, but the race condition required for exploitation may only occur infrequently.
Is there a fix available for CVE-2022-29582?
Yes, the fix for CVE-2022-29582 is available in Linux kernel version 5.17.3.