Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-2585

Опубликовано: 09 авг. 2022
Источник: redhat
CVSS3: 7.8

Описание

It was discovered that when exec'ing from a non-leader thread, armed POSIX CPU timers would be left on a list but freed, leading to a use-after-free.

A use-after-free flaw was found in the Linux kernel’s POSIX CPU timers functionality in the way a user creates and then deletes the timer in the non-leader thread of the program. This flaw allows a local user to crash or potentially escalate their privileges on the system.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernelNot affected
Red Hat Enterprise Linux 7kernel-rtNot affected
Red Hat Enterprise Linux 8kernelNot affected
Red Hat Enterprise Linux 8kernel-rtNot affected
Red Hat Enterprise Linux 9kernelFixedRHSA-2022:731802.11.2022
Red Hat Enterprise Linux 9kernel-rtFixedRHSA-2022:731902.11.2022
Red Hat Enterprise Linux 9kernelFixedRHSA-2022:731802.11.2022
Red Hat Enterprise Linux 9kpatch-patchFixedRHSA-2022:733002.11.2022

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=2114874kernel: posix cpu timer use-after-free may lead to local privilege escalation

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 1 года назад

It was discovered that when exec'ing from a non-leader thread, armed POSIX CPU timers would be left on a list but freed, leading to a use-after-free.

CVSS3: 5.3
nvd
больше 1 года назад

It was discovered that when exec'ing from a non-leader thread, armed POSIX CPU timers would be left on a list but freed, leading to a use-after-free.

CVSS3: 7.8
msrc
больше 1 года назад

Описание отсутствует

CVSS3: 5.3
debian
больше 1 года назад

It was discovered that when exec'ing from a non-leader thread, armed P ...

CVSS3: 7.8
fstec
почти 3 года назад

Уязвимость компонента POSIX CPU ядра операционной системы Linux, позволяющая нарушителю выполнить произвольный код

7.8 High

CVSS3