CVE-2022-33981: Use After Free
drivers/block/floppy.c in the Linux kernel before 5.17.6 is vulnerable to a denial of service, because of a concurrency use-after-free flaw after deallocating rawcmd in the rawcmdioctl function.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.262-1Fixed in 6.1.176-1Fixed in 6.1.180-1Fixed in 6.12.94-1Fixed in 6.12.101-1Fixed in 7.1.7-1Fixed in 7.1.8-1 - Upgrade
Upgrade
Linux kernel (drivers/block/floppy.c)to a version that resolves this vulnerability.Fixed in 5.17.6
Event History
Frequently Asked Questions
What is the severity of CVE-2022-33981?
CVE-2022-33981 is classified as a denial of service vulnerability due to a concurrency use-after-free flaw.
How do I fix CVE-2022-33981?
To fix CVE-2022-33981, upgrade the Linux kernel to version 5.17.6 or later.
Which versions of Linux kernel are affected by CVE-2022-33981?
CVE-2022-33981 affects Linux kernel versions prior to 5.17.6.
What systems are impacted by CVE-2022-33981?
CVE-2022-33981 impacts various distributions including Debian GNU/Linux version 9.0 and 10.0.
What can happen if CVE-2022-33981 is exploited?
Exploitation of CVE-2022-33981 may lead to a denial of service, causing the system to become unresponsive.