cbcvebase.
CVE-2022-1116
published 2022-05-17

CVE-2022-1116: Integer Overflow or Wraparound vulnerability in io_uring of Linux Kernel allows local attacker to cause memory corruption and escalate privileges to root. This…

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
Integer Overflow or Wraparound vulnerability in io_uring of Linux Kernel allows local attacker to cause memory corruption and escalate privileges to root. This issue affects: Linux Kernel versions prior to 5.4.189; version 5.4.24 and later versions.

Affected

9 ranges
VendorProductVersion rangeFixed in
debianlinux
linuxkernel>= 5.4.24 < unspecifiedunspecified
linuxkernel>= unspecified < 5.4.1895.4.189
linuxlinux_kernel>= 0 < 5.4.0-113.1275.4.0-113.127
linuxlinux_kernel>= 0 < 4.4.0-227.2614.4.0-227.261
linuxlinux_kernel>= 0 < 4.15.0-180.1894.15.0-180.189
linuxlinux_kernel>= 0 < 5.4.0-117.1325.4.0-117.132
linuxlinux_kernel>= 0 < 5.15.0-37.395.15.0-37.39
linuxlinux_kernel>= 5.4.24 < 5.4.1895.4.189

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH