CVE-2022-1011
Severity
7.8HIGH
EPSS
0.2%
top 55.47%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 18
Latest updateJul 28
Description
A use-after-free flaw was found in the Linux kernel’s FUSE filesystem in the way a user triggers write(). This flaw allows a local user to gain unauthorized access to data from the FUSE filesystem, resulting in privilege escalation.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9
Affected Packages7 packages
Also affects: Debian Linux 10.0, 9.0, Enterprise Linux 6.0, 7.0, 8.0, 8.6, 8, Fedora 34, 35
🔴Vulnerability Details
5OSV▶
linux, linux-aws, linux-aws-hwe, linux-azure, linux-azure-4.15, linux-dell300x, linux-gcp, linux-gcp-4.15, linux-hwe, linux-kvm, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities↗2022-07-13
GHSA▶
GHSA-8x5v-3jgc-w6jf: A flaw use after free in the Linux kernel FUSE filesystem was found in the way user triggers write()↗2022-03-19
CVEList▶
CVE-2022-1011: A use-after-free flaw was found in the Linux kernel’s FUSE filesystem in the way a user triggers write()↗2022-03-18
OSV▶
CVE-2022-1011: A use-after-free flaw was found in the Linux kernel’s FUSE filesystem in the way a user triggers write()↗2022-03-18
📋Vendor Advisories
7Microsoft▶
A use-after-free flaw was found in the Linux kernel’s FUSE filesystem in the way a user triggers write(). This flaw allows a local user to gain unauthorized access to data from the FUSE filesystem res↗2022-03-08