CVE-2022-1011

CWE-416Use After Free13 documents8 sources
Severity
7.8HIGH
EPSS
0.2%
top 55.47%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 18
Latest updateJul 28

Description

A use-after-free flaw was found in the Linux kernel’s FUSE filesystem in the way a user triggers write(). This flaw allows a local user to gain unauthorized access to data from the FUSE filesystem, resulting in privilege escalation.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages7 packages

NVDlinux/linux_kernel< 5.17+1
Debianlinux< 5.10.106-1+3
CVEListV5kernelLinux kernel 5.16-rc8

Also affects: Debian Linux 10.0, 9.0, Enterprise Linux 6.0, 7.0, 8.0, 8.6, 8, Fedora 34, 35

🔴Vulnerability Details

5
OSV
linux-azure vulnerabilities2022-07-28
OSV
linux, linux-aws, linux-aws-hwe, linux-azure, linux-azure-4.15, linux-dell300x, linux-gcp, linux-gcp-4.15, linux-hwe, linux-kvm, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities2022-07-13
GHSA
GHSA-8x5v-3jgc-w6jf: A flaw use after free in the Linux kernel FUSE filesystem was found in the way user triggers write()2022-03-19
CVEList
CVE-2022-1011: A use-after-free flaw was found in the Linux kernel’s FUSE filesystem in the way a user triggers write()2022-03-18
OSV
CVE-2022-1011: A use-after-free flaw was found in the Linux kernel’s FUSE filesystem in the way a user triggers write()2022-03-18

📋Vendor Advisories

7
Ubuntu
Linux kernel (Azure) vulnerabilities2022-07-28
Ubuntu
Linux kernel vulnerabilities2022-07-13
Ubuntu
Linux kernel vulnerabilities2022-06-08
Ubuntu
Linux kernel (OEM) vulnerabilities2022-04-20
Microsoft
A use-after-free flaw was found in the Linux kernel’s FUSE filesystem in the way a user triggers write(). This flaw allows a local user to gain unauthorized access to data from the FUSE filesystem res2022-03-08