CVE-2022-4139

HIGH

Linux Kernel - Use-After-Free in i915 GPU Driver

Title source: llm
STIX 2.1

Description

An incorrect TLB flush issue was found in the Linux kernel’s GPU i915 kernel driver, potentially leading to random memory corruption or data leaks. This flaw could allow a local user to crash the system or escalate their privileges on the system.

References (3)

Core 3
Core References
Issue Tracking, Patch, Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2147572

Scores

CVSS v3 7.8
EPSS 0.0025
EPSS Percentile 16.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-401 CWE-281
Status published
Products (2)
linux/linux_kernel 6.1 (7 CPE variants)
linux/linux_kernel 5.4 - 5.4.226
Published Jan 27, 2023
Tracked Since Feb 18, 2026