CVE-2022-1729Race Condition within a Thread in Kernel

Severity
7.0HIGHNVD
EPSS
0.1%
top 80.91%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 1
Latest updateOct 6

Description

A race condition was found the Linux kernel in perf_event_open() which can be exploited by an unprivileged user to gain root privileges. The bug allows to build several exploit primitives such as kernel address information leak, arbitrary execution, etc.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.0 | Impact: 5.9

Affected Packages4 packages

NVDlinux/linux_kernel3.2.853.3+9
Debianlinux/linux_kernel< 5.10.120-1+3
CVEListV5linux/linux_kernellinux kernel 5.18 rc9

Patches

🔴Vulnerability Details

2
OSV
CVE-2022-1729: A race condition was found the Linux kernel in perf_event_open() which can be exploited by an unprivileged user to gain root privileges2022-09-01
CVEList
CVE-2022-1729: A race condition was found the Linux kernel in perf_event_open() which can be exploited by an unprivileged user to gain root privileges2022-09-01

📋Vendor Advisories

15
Ubuntu
Linux kernel (GCP) vulnerabilities2022-10-06
Ubuntu
Linux kernel (GKE) vulnerabilities2022-10-04
Ubuntu
Linux kernel vulnerabilities2022-09-30
Ubuntu
Linux kernel (Azure CVM) vulnerabilities2022-09-26
Ubuntu
Linux kernel (Raspberry Pi) vulnerabilities2022-09-22
CVE-2022-1729 — Race Condition within a Thread | cvebase