CVE-2022-4095Use After Free in Kernel

Severity
7.8HIGHNVD
OSV7.0OSV5.5OSV4.4
EPSS
0.0%
top 96.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 22
Latest updateJun 15

Description

A use-after-free flaw was found in Linux kernel before 5.19.2. This issue occurs in cmd_hdl_filter in drivers/staging/rtl8712/rtl8712_cmd.c, allowing an attacker to launch a local denial of service attack and gain escalation of privileges.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages16 packages

NVDlinux/linux_kernel2.6.374.9.328+7
Debianlinux/linux_kernel< 5.10.148-1+3
Ubuntulinux/linux_kernel< 4.15.0-201.212+3
CVEListV5linux/linux_kernelLinux Kernel prior to kernel 6.0 rc4
debiandebian/linux< linux 5.19.11-1 (bookworm)

Patches

🔴Vulnerability Details

12
OSV
linux-oem-5.17 vulnerabilities2023-05-10
OSV
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities2023-04-26
GHSA
GHSA-cfq4-hg5x-x4r5: A use-after-free flaw was found in Linux kernel before 52023-03-22
OSV
CVE-2022-4095: A use-after-free flaw was found in Linux kernel before 52023-03-22
OSV
linux-gke-5.15 vulnerabilities2023-02-15

📋Vendor Advisories

20
CISA ICS
Siemens SIMATIC S7-1500 TM MFP Linux Kernel2023-06-15
Ubuntu
Linux kernel (OEM) vulnerabilities2023-05-10
Ubuntu
Linux kernel vulnerabilities2023-04-26
Microsoft
A use-after-free flaw was found in Linux kernel before 5.19.2. This issue occurs in cmd_hdl_filter in drivers/staging/rtl8712/rtl8712_cmd.c allowing an attacker to launch a local denial of service att2023-03-14
Ubuntu
Linux kernel (GKE) vulnerabilities2023-02-15

💬Community

1
HackerOne
CVE-2022-35260: .netrc parser out-of-bounds access2022-10-27
CVE-2022-4095 — Use After Free in Linux Kernel | cvebase