cbcvebase.
CVE-2022-1729
published 2022-09-01

CVE-2022-1729: A race condition was found the Linux kernel in perf_event_open() which can be exploited by an unprivileged user to gain root privileges. The bug allows to…

PriorityP338high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
0.31%
23.3th percentile
A race condition was found the Linux kernel in perf_event_open() which can be exploited by an unprivileged user to gain root privileges. The bug allows to build several exploit primitives such as kernel address information leak, arbitrary execution, etc.

Affected

25 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.17.11-1 (bookworm)linux 5.17.11-1 (bookworm)
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.120-15.10.120-1
linuxlinux_kernel>= 0 < 5.17.11-15.17.11-1
linuxlinux_kernel>= 0 < 5.17.11-15.17.11-1
linuxlinux_kernel>= 0 < 5.17.11-15.17.11-1
linuxlinux_kernel>= 0 < 4.15.0-191.2024.15.0-191.202
linuxlinux_kernel>= 0 < 5.4.0-126.1425.4.0-126.142
linuxlinux_kernel>= 0 < 5.15.0-47.515.15.0-47.51
linuxlinux_kernel>= 0 < 4.4.0-234.2684.4.0-234.268
linuxlinux_kernel>= 3.16.40 < 3.173.17
linuxlinux_kernel>= 3.18.54 < 3.193.19
linuxlinux_kernel>= 3.2.85 < 3.33.3
linuxlinux_kernel>= 4.0.0 < 4.9.3164.9.316
linuxlinux_kernel>= 4.10 < 4.14.2814.14.281
linuxlinux_kernel>= 4.15 < 4.19.2454.19.245
linuxlinux_kernel>= 4.20 < 5.4.1965.4.196
linuxlinux_kernel>= 5.11 < 5.15.425.15.42
linuxlinux_kernel>= 5.16 < 5.17.105.17.10
linuxlinux_kernel>= 5.5.0 < 5.10.1185.10.118
netapphci_baseboard_management_controller
netapphci_baseboard_management_controller
netapphci_baseboard_management_controller
netapphci_baseboard_management_controller
paloaltopan-os

CVSS provenance

nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.0HIGH
vendor_debian7.0HIGH
vendor_redhat7.0HIGH
vendor_ubuntu6.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.