CVE-2022-2588

MEDIUM

Linux kernel - Use After Free

Title source: llm

Description

It was discovered that the cls_route filter implementation in the Linux kernel would not remove an old filter from the hashtable before freeing it if its handle had the value 0.

Exploits (9)

nomisec WORKING POC 485 stars
by Markakd · poc
https://github.com/Markakd/CVE-2022-2588
nomisec WORKING POC 12 stars
by BassamGraini · poc
https://github.com/BassamGraini/CVE-2022-2588
nomisec WORKING POC 11 stars
by veritas501 · poc
https://github.com/veritas501/CVE-2022-2588
nomisec WRITEUP 10 stars
by nopgadget · poc
https://github.com/nopgadget/CVE-2022-2588
nomisec WORKING POC 7 stars
by pirenga · poc
https://github.com/pirenga/2022-LPE-UAF
nomisec WORKING POC 4 stars
by konoha279 · poc
https://github.com/konoha279/2022-LPE-UAF
nomisec WORKING POC 1 stars
by ASkyeye · poc
https://github.com/ASkyeye/2022-LPE-UAF
nomisec WORKING POC
by dom4570 · poc
https://github.com/dom4570/CVE-2022-2588
nomisec WORKING POC
by Igr1s-red · poc
https://github.com/Igr1s-red/CVE-2022-2588

Scores

CVSS v3 5.3
EPSS 0.5936
EPSS Percentile 98.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H

Classification

CWE
CWE-415 CWE-416
Status published

Affected Products (6)

linux/linux_kernel < 4.9.326
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux

Timeline

Published Jan 08, 2024
Tracked Since Feb 18, 2026