CVE-2022-2961

CVSS 7.0 - HIGH
Description

A use-after-free flaw was found in the Linux kernel’s PLP Rose functionality in the way a user triggers a race condition by calling bind while simultaneously triggering the rose_bind() function. This flaw allows a local user to crash or potentially escalate their privileges on the system.

Affected Products
13
Vendor Product Version
linux linux_kernel All versions
linux linux_kernel 6.0
fedoraproject fedora 36
netapp h300s_firmware -
netapp h300s -
netapp h500s_firmware -
netapp h500s -
netapp h700s_firmware -
netapp h700s -
netapp h410s_firmware -
netapp h410s -
netapp h410c_firmware -
netapp h410c -
Weakness Types
CWE-416 CWE-362
CVE Information
CVE ID:
CVE-2022-2961
Published:
2022-08-29
Modified:
2024-11-21
CVSS Score:
7.0
Severity:
HIGH
Vector:
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Vendors
netapp linux fedoraproject
Quick Actions
CVSS Severity Scale
0.0 - 3.9 LOW
4.0 - 6.9 MEDIUM
7.0 - 8.9 HIGH
9.0 - 10.0 CRITICAL