imPC@ndo IT

Tracker / CVE-2022-1998

CVE-2022-1998

High 7.8

A use after free in the Linux kernel File System notify functionality was found in the way user triggers copy_info_records_to_user() call to fail in copy_event_to_user(). A local user could use this flaw to crash the system or potentially escalate their privileges on the system.

Affected products and versions

fedoraproject fedora
linux linux_kernel · 5.10.46 → 5.10.97
linux linux_kernel · 5.12.12 → 5.15.20
linux linux_kernel · 5.16.0 → 5.16.6
netapp h300s_firmware
netapp h410c_firmware
netapp h410s_firmware
netapp h500s_firmware
netapp h700s_firmware
redhat enterprise_linux

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References