CVE-2022-2978: Use After Free
A flaw use after free in the Linux kernel NILFS file system was found in the way user triggers function securityinodealloc to fail with following call to function nilfsmdtdestroy. A local user could use this flaw to crash the system or potentially escalate their privileges on the system.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-2978?
CVE-2022-2978 is considered a high-severity vulnerability that could allow local users to crash the system or escalate privileges.
How do I fix CVE-2022-2978?
To fix CVE-2022-2978, upgrade to the patched versions of the Linux kernel, including 5.10.223-1, 5.10.226-1, 6.1.123-1, 6.1.119-1, 6.12.11-1, or 6.12.12-1.
Who is affected by CVE-2022-2978?
CVE-2022-2978 affects local users of Linux systems running vulnerable versions of the kernel, particularly those exploiting the NILFS file system.
What type of vulnerability is CVE-2022-2978?
CVE-2022-2978 is a use-after-free vulnerability in the Linux kernel that can be exploited to potentially escalate privileges.
When was CVE-2022-2978 disclosed?
CVE-2022-2978 was disclosed in August 2022.