CVE-2022-29582
published 2022-04-22CVE-2022-29582: In the Linux kernel before 5.17.3, fs/io_uring.c has a use-after-free due to a race condition in io_uring timeouts. This can be triggered by a local user who…
PriorityP433high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
0.77%
52.2th percentile
In the Linux kernel before 5.17.3, fs/io_uring.c has a use-after-free due to a race condition in io_uring timeouts. This can be triggered by a local user who has no access to any user namespace; however, the race condition perhaps can only be exploited infrequently.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | linux | < linux 5.17.3-1 (bookworm) | linux 5.17.3-1 (bookworm) |
| android | — | — | |
| linux | linux_kernel | < 5.17.3 | 5.17.3 |
| linux | linux_kernel | >= 0 < 5.10.113-1 | 5.10.113-1 |
| linux | linux_kernel | >= 0 < 5.17.3-1 | 5.17.3-1 |
| linux | linux_kernel | >= 0 < 5.17.3-1 | 5.17.3-1 |
| linux | linux_kernel | >= 0 < 5.17.3-1 | 5.17.3-1 |
| msrc | cbl2_kernel_5.15.37.1-2_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| msrc | cm1_kernel_5.10.116.1-1_on_cbl_mariner_1.0 | — | — |
CVSS provenance
nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv7.0HIGH
vendor_debian7.0HIGH
vendor_msrc7.0HIGH
vendor_redhat7.0HIGH
vendor_oracle5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Linux Kernel up to 5.17.2 User Namespace fs/io_uring.c io_uring use after free (EUVD-2022-33915 / Nessus ID 236670)
vuldb·2026-05-23·CVSS 7.0
CVE-2022-29582 [HIGH] Linux Kernel up to 5.17.2 User Namespace fs/io_uring.c io_uring use after free (EUVD-2022-33915 / Nessus ID 236670)
A vulnerability described as critical has been identified in Linux Kernel up to 5.17.2. Affected is the function io_uring of the file fs/io_uring.c of the component User Namespace Handler. Executing a manipulation can lead to use after free.
This vulnerability is handled as CVE-2022-29582. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is recommended.
OSV
CVE-2022-29582: In fs, there is a possible use-after-free due to a race condition in io_uring timeouts
osv·2022-09-01
CVE-2022-29582 CVE-2022-29582: In fs, there is a possible use-after-free due to a race condition in io_uring timeouts
In fs, there is a possible use-after-free due to a race condition in io_uring timeouts. This could lead to local escalation of privileges with no additional execution privileges needed. User interaction is not needed for exploitation
GHSA
GHSA-52p4-cqpv-xm5j: In the Linux kernel before 5
ghsa_unreviewed·2022-04-23
CVE-2022-29582 [HIGH] CWE-362 GHSA-52p4-cqpv-xm5j: In the Linux kernel before 5
In the Linux kernel before 5.17.3, fs/io_uring.c has a use-after-free due to a race condition in io_uring timeouts. This can be triggered by a local user who has no access to any user namespace; however, the race condition perhaps can only be exploited infrequently.
OSV
CVE-2022-29582: In the Linux kernel before 5
osv·2022-04-22·CVSS 7.0
CVE-2022-29582 [HIGH] CVE-2022-29582: In the Linux kernel before 5
In the Linux kernel before 5.17.3, fs/io_uring.c has a use-after-free due to a race condition in io_uring timeouts. This can be triggered by a local user who has no access to any user namespace; however, the race condition perhaps can only be exploited infrequently.
Oracle
Oracle Oracle Communications Risk Matrix: Platform (JetBrains Kotlin) — CVE-2020-29582
vendor_oracle·2022-10-15·CVSS 5.3
CVE-2020-29582 [MEDIUM] Oracle Oracle Communications Risk Matrix: Platform (JetBrains Kotlin) — CVE-2020-29582
Oracle Oracle Communications Risk Matrix: Platform (JetBrains Kotlin) vulnerability
CVE: CVE-2020-29582
CVSS: 5.3
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2022 (OCT 2022)
Android
CVE-2022-29582: fs
vendor_android·2022-09-01·CVSS 7.0
CVE-2022-29582 [HIGH] CVE-2022-29582: fs
Android Security Bulletin 2022-09-01
CVE: CVE-2022-29582
Severity: HIGH
Type: EoP
Component: fs
References: A-231494876
Upstream kernel
Oracle
Oracle Oracle Communications Risk Matrix: Policy (Kotlin) — CVE-2020-29582
vendor_oracle·2022-04-15·CVSS 5.3
CVE-2020-29582 [MEDIUM] Oracle Oracle Communications Risk Matrix: Policy (Kotlin) — CVE-2020-29582
Oracle Oracle Communications Risk Matrix: Policy (Kotlin) vulnerability
CVE: CVE-2020-29582
CVSS: 5.3
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2022 (APR 2022)
Microsoft
In the Linux kernel before 5.17.3 fs/io_uring.c has a use-after-free due to a race condition in io_uring timeouts. This can be triggered by a local user who has no access to any user namespace; howeve
vendor_msrc·2022-04-12·CVSS 7.0
CVE-2022-29582 [HIGH] CWE-362 In the Linux kernel before 5.17.3 fs/io_uring.c has a use-after-free due to a race condition in io_uring timeouts. This can be triggered by a local user who has no access to any user namespace; howeve
In the Linux kernel before 5.17.3 fs/io_uring.c has a use-after-free due to a race condition in io_uring timeouts. This can be triggered by a local user who has no access to any user namespace; however the race condition perhaps can only be exploited infrequently.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If
Red Hat
kernel: Race condition that allows container escape to system root
vendor_redhat·2022-04-08·CVSS 7.0
CVE-2022-29582 [HIGH] CWE-416 kernel: Race condition that allows container escape to system root
kernel: Race condition that allows container escape to system root
In the Linux kernel before 5.17.3, fs/io_uring.c has a use-after-free due to a race condition in io_uring timeouts. This can be triggered by a local user who has no access to any user namespace; however, the race condition perhaps can only be exploited infrequently.
A use-after-free flaw was found in the Linux kernel’s io_uring interface subsystem in the way a user triggers a race condition between timeout flush and removal. This flaw allows a local user to crash or escalate their privileges on the system.
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterpr
Oracle
Oracle Oracle Communications Risk Matrix: SCP (Kotlin) — CVE-2020-29582
vendor_oracle·2022-01-15·CVSS 5.3
CVE-2020-29582 [MEDIUM] Oracle Oracle Communications Risk Matrix: SCP (Kotlin) — CVE-2020-29582
Oracle Oracle Communications Risk Matrix: SCP (Kotlin) vulnerability
CVE: CVE-2020-29582
CVSS: 5.3
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2022 (JAN 2022)
Debian
CVE-2022-29582: linux - In the Linux kernel before 5.17.3, fs/io_uring.c has a use-after-free due to a r...
vendor_debian·2022·CVSS 7.0
CVE-2022-29582 [HIGH] CVE-2022-29582: linux - In the Linux kernel before 5.17.3, fs/io_uring.c has a use-after-free due to a r...
In the Linux kernel before 5.17.3, fs/io_uring.c has a use-after-free due to a race condition in io_uring timeouts. This can be triggered by a local user who has no access to any user namespace; however, the race condition perhaps can only be exploited infrequently.
Scope: local
bookworm: resolved (fixed in 5.17.3-1)
bullseye: resolved (fixed in 5.10.113-1)
forky: resolved (fixed in 5.17.3-1)
sid: resolved (fixed in 5.17.3-1)
trixie: resolved (fixed in 5.17.3-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2022/04/22/4http://www.openwall.com/lists/oss-security/2022/08/08/3http://www.openwall.com/lists/oss-security/2024/04/24/3https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.17.3https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=e677edbcabee849bfdd43f1602bccbecf736a646https://github.com/Ruia-ruia/CVE-2022-29582-Exploithttps://github.com/torvalds/linux/commit/e677edbcabee849bfdd43f1602bccbecf736a646https://ruia-ruia.github.io/2022/08/05/CVE-2022-29582-io-uring/https://www.debian.org/security/2022/dsa-5127https://www.openwall.com/lists/oss-security/2022/04/22/3http://www.openwall.com/lists/oss-security/2022/04/22/4http://www.openwall.com/lists/oss-security/2022/08/08/3http://www.openwall.com/lists/oss-security/2024/04/24/3https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.17.3https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=e677edbcabee849bfdd43f1602bccbecf736a646https://github.com/Ruia-ruia/CVE-2022-29582-Exploithttps://github.com/torvalds/linux/commit/e677edbcabee849bfdd43f1602bccbecf736a646https://ruia-ruia.github.io/2022/08/05/CVE-2022-29582-io-uring/https://www.debian.org/security/2022/dsa-5127https://www.openwall.com/lists/oss-security/2022/04/22/3
2022-04-22
Published