CVE-2022-2961: Use After Free
A use-after-free flaw was found in the Linux kernel’s PLP Rose functionality in the way a user triggers a race condition by calling bind while simultaneously triggering the rosebind() function. This flaw allows a local user to crash or potentially escalate their privileges on the system.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-2961?
CVE-2022-2961 is a use-after-free vulnerability in the Linux kernel's PLP Rose functionality that allows a local user to crash or potentially escalate privileges.
Which software is affected by CVE-2022-2961?
The Linux kernel versions up to and including 6.0 and Fedora 36 are affected by CVE-2022-2961.
How severe is CVE-2022-2961?
CVE-2022-2961 has a severity rating of high (7 out of 10).
How can I fix CVE-2022-2961?
Apply the necessary updates or patches provided by the Linux kernel or Fedora to fix CVE-2022-2961.
Where can I find more information about CVE-2022-2961?
You can find more information about CVE-2022-2961 on the Red Hat and NetApp security advisories provided in the references: [Red Hat Advisory](https://access.redhat.com/security/cve/CVE-2022-2961) and [NetApp Advisory](https://security.netapp.com/advisory/ntap-20230214-0004/).