CVE-2022-1508
published 2022-08-31CVE-2022-1508: An out-of-bounds read flaw was found in the Linux kernel’s io_uring module in the way a user triggers the io_read() function with some special parameters. This…
PriorityP424medium6.1CVSS 3.1
AVLACLPRLUINSUCLINAH
EPSS
0.24%
14.5th percentile
An out-of-bounds read flaw was found in the Linux kernel’s io_uring module in the way a user triggers the io_read() function with some special parameters. This flaw allows a local user to read some memory out of bounds.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.15.3-1 (bookworm) | linux 5.15.3-1 (bookworm) |
| linux | linux_kernel | < 5.15 | 5.15 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.120-1 | 5.10.120-1 |
| linux | linux_kernel | >= 0 < 5.15.3-1 | 5.15.3-1 |
| linux | linux_kernel | >= 0 < 5.15.3-1 | 5.15.3-1 |
| linux | linux_kernel | >= 0 < 5.15.3-1 | 5.15.3-1 |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cm1_kernel_5.10.144.1-1_on_cbl_mariner_1.0 | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H
osv6.1MEDIUM
vendor_debian6.1MEDIUM
vendor_msrc6.1MEDIUM
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
An out-of-bounds read flaw was found in the Linux kernel’s io_uring module in the way a user triggers the io_read() function with some special parameters. This flaw allows a local user to read some me
vendor_msrc·2022-08-09·CVSS 6.1
CVE-2022-1508 [MEDIUM] CWE-125 An out-of-bounds read flaw was found in the Linux kernel’s io_uring module in the way a user triggers the io_read() function with some special parameters. This flaw allows a local user to read some me
An out-of-bounds read flaw was found in the Linux kernel’s io_uring module in the way a user triggers the io_read() function with some special parameters. This flaw allows a local user to read some memory out of bounds.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified,
Debian
CVE-2022-1508: linux - An out-of-bounds read flaw was found in the Linux kernel’s io_uring module in th...
vendor_debian·2022·CVSS 6.1
CVE-2022-1508 [MEDIUM] CVE-2022-1508: linux - An out-of-bounds read flaw was found in the Linux kernel’s io_uring module in th...
An out-of-bounds read flaw was found in the Linux kernel’s io_uring module in the way a user triggers the io_read() function with some special parameters. This flaw allows a local user to read some memory out of bounds.
Scope: local
bookworm: resolved (fixed in 5.15.3-1)
bullseye: resolved (fixed in 5.10.120-1)
forky: resolved (fixed in 5.15.3-1)
sid: resolved (fixed in 5.15.3-1)
trixie: resolved (fixed in 5.15.3-1)
Red Hat
kernel: out-of-bounds read in iov_iter_revert() in lib/iov_iter.c
vendor_redhat·2021-08-23·CVSS 6.1
CVE-2022-1508 [MEDIUM] CWE-125 kernel: out-of-bounds read in iov_iter_revert() in lib/iov_iter.c
kernel: out-of-bounds read in iov_iter_revert() in lib/iov_iter.c
An out-of-bounds read flaw was found in the Linux kernel’s io_uring module in the way a user triggers the io_read() function with some special parameters. This flaw allows a local user to read some memory out of bounds.
An out-of-bounds read flaw was found in the Linux kernel’s io_uring module in the way a user triggers the io_read() function with some special parameters. This flaw allows a local user to read some memory out of bounds.
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux
GHSA
GHSA-mjrx-6f7j-qvf7: An out-of-bounds read flaw was found in the Linux kernel’s io_uring module in the way a user triggers the io_read() function with some special paramet
ghsa_unreviewed·2022-09-01
CVE-2022-1508 [MEDIUM] CWE-125 GHSA-mjrx-6f7j-qvf7: An out-of-bounds read flaw was found in the Linux kernel’s io_uring module in the way a user triggers the io_read() function with some special paramet
An out-of-bounds read flaw was found in the Linux kernel’s io_uring module in the way a user triggers the io_read() function with some special parameters. This flaw allows a local user to read some memory out of bounds.
OSV
CVE-2022-1508: An out-of-bounds read flaw was found in the Linux kernel’s io_uring module in the way a user triggers the io_read() function with some special paramet
osv·2022-08-31·CVSS 6.1
CVE-2022-1508 [MEDIUM] CVE-2022-1508: An out-of-bounds read flaw was found in the Linux kernel’s io_uring module in the way a user triggers the io_read() function with some special paramet
An out-of-bounds read flaw was found in the Linux kernel’s io_uring module in the way a user triggers the io_read() function with some special parameters. This flaw allows a local user to read some memory out of bounds.
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: Use-after-free condition in Google Chrome WebGPU
blogs_talos·2022-07-14·CVSS 8.8
[HIGH] Vulnerability Spotlight: Use-after-free condition in Google Chrome WebGPU
Piotr Bania of Cisco Talos discovered this vulnerability.
Cisco Talos recently discovered an exploitable use-after-free vulnerability in Google Chrome’s WebGPU standard.
Google Chrome is a cross-platform web browser — and Chromium is the open-source version of the browser that both Google and other software developers use as the basis to build their browsers, as well. This specific vulnerability exists in WebGPU, which is a JavaScript API for processing accelerated 3-D graphics and other functions in the browser. TALOS-2022-1508 (CVE-2022-2399) occurs if the user opens a specially crafted web page in Chrome. That page could trigger a use-after-free condition in the application, which an attacker could then use to manipulate the browser in additional ways.
Cisco Talos worked with Google
Talos
Vulnerability Spotlight: Use-after-free condition in Google Chrome WebGPU
blogs_talos·2022-07-14·CVSS 8.8
[HIGH] Vulnerability Spotlight: Use-after-free condition in Google Chrome WebGPU
## Vulnerability Spotlight: Use-after-free condition in Google Chrome WebGPU
Piotr Bania of Cisco Talos discovered this vulnerability.
Cisco Talos recently discovered an exploitable use-after-free vulnerability in Google Chrome’s WebGPU standard.
Google Chrome is a cross-platform web browser — and Chromium is the open-source version of the browser that both Google and other software developers use as the basis to build their browsers, as well. This specific vulnerability exists in WebGPU, which is a JavaScript API for processing accelerated 3-D graphics and other functions in the browser. TALOS-2022-1508 (CVE-2022-2399) occurs if the user opens a specially crafted web page in Chrome. That page could trigger a use-after-free condition in the application, which an attacker could then use
https://access.redhat.com/security/cve/CVE-2022-1508https://bugzilla.redhat.com/show_bug.cgi?id=2075533https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=89c2b3b74918200e46699338d7bcc19b1ea12110https://ubuntu.com/security/CVE-2022-1508https://access.redhat.com/security/cve/CVE-2022-1508https://bugzilla.redhat.com/show_bug.cgi?id=2075533https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=89c2b3b74918200e46699338d7bcc19b1ea12110https://ubuntu.com/security/CVE-2022-1508
2022-08-31
Published