CVE-2022-1998Use After Free in Kernel

CWE-416Use After Free9 documents7 sources
Severity
7.8HIGHNVD
OSV7.0
EPSS
0.1%
top 68.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 9
Latest updateMay 3

Description

A use after free in the Linux kernel File System notify functionality was found in the way user triggers copy_info_records_to_user() call to fail in copy_event_to_user(). A local user could use this flaw to crash the system or potentially escalate their privileges on the system.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages4 packages

NVDlinux/linux_kernel5.10.465.10.97+2
Debianlinux/linux_kernel< 5.10.103-1+3
Ubuntulinux/linux_kernel< 4.4.0-253.287
CVEListV5linux/linux_kernelLinux kernel 5.17-rc3

Also affects: Enterprise Linux 9.0, Fedora 35

Patches

🔴Vulnerability Details

4
OSV
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities2024-04-19
GHSA
GHSA-2789-cv5q-pwgx: A use after free in the Linux kernel File System notify functionality was found in the way user triggers copy_info_records_to_user() call to fail in c2022-06-10
OSV
CVE-2022-1998: A use after free in the Linux kernel File System notify functionality was found in the way user triggers copy_info_records_to_user() call to fail in c2022-06-09
CVEList
CVE-2022-1998: A use after free in the Linux kernel File System notify functionality was found in the way user triggers copy_info_records_to_user() call to fail in c2022-06-09

📋Vendor Advisories

4
Red Hat
kernel: clean up hook list when offload flags check fails2024-05-03
Microsoft
A use after free in the Linux kernel File System notify functionality was found in the way user triggers copy_info_records_to_user() call to fail in copy_event_to_user(). A local user could use this f2022-06-14
Red Hat
kernel: fanotify misuses fd_install() which could lead to use-after-free2022-01-27
Debian
CVE-2022-1998: linux - A use after free in the Linux kernel File System notify functionality was found ...2022
CVE-2022-1998 — Use After Free in Linux Kernel | cvebase