CVE-2022-1729
HIGHLinux Kernel 3.2.85-3.3 - Unauthenticated Race Condition in perf_event_open()
Title source: llmDescription
A race condition was found the Linux kernel in perf_event_open() which can be exploited by an unprivileged user to gain root privileges. The bug allows to build several exploit primitives such as kernel address information leak, arbitrary execution, etc.
References (3)
Core 3
Core References
Mailing List, Patch, Vendor Advisory
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=3ac6487e584a1eb54071dbe1212e05b884136704
Patch, Third Party Advisory
https://security.netapp.com/advisory/ntap-20230214-0006/
Mailing List, Patch, Third Party Advisory
https://www.openwall.com/lists/oss-security/2022/05/20/2
Scores
CVSS v3
7.0
EPSS
0.0007
EPSS Percentile
21.2%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-362
CWE-366
Status
published
Products (5)
linux/linux_kernel
3.2.85 - 3.3
netapp/hci_baseboard_management_controller
h300s
netapp/hci_baseboard_management_controller
h410s
netapp/hci_baseboard_management_controller
h500s
netapp/hci_baseboard_management_controller
h700s
Published
Sep 01, 2022
Tracked Since
Feb 18, 2026