CVE-2022-2978
HIGHLinux Kernel 2.6.12-4.9.330 - Use-After-Free in NILFS File System
Title source: llmDescription
A flaw use after free in the Linux kernel NILFS file system was found in the way user triggers function security_inode_alloc to fail with following call to function nilfs_mdt_destroy. A local user could use this flaw to crash the system or potentially escalate their privileges on the system.
References (2)
Core 2
Core References
Mailing List, Third Party Advisory mailing-list
https://lists.debian.org/debian-lts-announce/2022/12/msg00034.html
Scores
CVSS v3
7.8
EPSS
0.0008
EPSS Percentile
23.6%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-416
Status
published
Products (2)
debian/debian_linux
10.0
linux/linux_kernel
2.6.12 - 4.9.331
Published
Aug 24, 2022
Tracked Since
Feb 18, 2026