imPC@ndo IT

Tracker / CVE-2022-24122

CVE-2022-24122

High 7.8

kernel/ucount.c in the Linux kernel 5.14 through 5.16.4, when unprivileged user namespaces are enabled, allows a use-after-free and privilege escalation because a ucounts object can outlive its namespace.

Affected products and versions

fedoraproject fedora
linux linux_kernel · 5.14 → 5.15.19
linux linux_kernel · 5.16 → 5.16.5
netapp h300e_firmware
netapp h300s_firmware
netapp h410c_firmware
netapp h410s_firmware
netapp h500e_firmware
netapp h500s_firmware
netapp h700e_firmware
netapp h700s_firmware

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References