CVE-2022-1652

HIGH

Linux Kernel 2.6.12-4.9.315 - Use-After-Free in bad_flp_intr Function

Title source: llm
STIX 2.1

Description

Linux Kernel could allow a local attacker to execute arbitrary code on the system, caused by a concurrency use-after-free flaw in the bad_flp_intr function. By executing a specially-crafted program, an attacker could exploit this vulnerability to execute arbitrary code or cause a denial of service condition on the system.

References (5)

Core 5
Core References
Not Applicable x_refsource_misc
https://francozappa.github.io/about-bias/
Issue Tracking, Not Applicable x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=1832397
Not Applicable, Third Party Advisory, US Government Resource x_refsource_misc
https://kb.cert.org/vuls/id/647177/
Third Party Advisory vendor-advisory x_refsource_debian
https://www.debian.org/security/2022/dsa-5173
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20220722-0002/

Scores

CVSS v3 7.8
EPSS 0.0075
EPSS Percentile 73.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-416
Status published
Products (8)
debian/debian_linux 10.0
linux/linux_kernel 2.6.12 - 4.9.316
netapp/h300s_firmware
netapp/h410c_firmware
netapp/h410s_firmware
netapp/h500s_firmware
netapp/h700s_firmware
redhat/enterprise_linux 9.0
Published Jun 02, 2022
Tracked Since Feb 18, 2026