CVE-2022-41222
Published on: Not Yet Published
Last Modified on: 02/15/2023 08:15:00 PM UTC
Certain versions of Debian Linux from Debian contain the following vulnerability:
mm/mremap.c in the Linux kernel before 5.13.3 has a use-after-free via a stale TLB because an rmap lock is not held during a PUD move.
- CVE-2022-41222 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
CVSS3 Score: 7 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
LOCAL | HIGH | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Kernel Live Patch Security Notice LNS-0091-1 ≈ Packet Storm | packetstormsecurity.com text/html |
![]() |
cdn.kernel.org text/plain |
![]() | |
Linux Stable 5.4 / 5.10 Use-After-Free / Race Condition ≈ Packet Storm | packetstormsecurity.com text/html |
![]() |
2347 - project-zero - Project Zero - Monorail | bugs.chromium.org text/html |
![]() |
[SECURITY] [DLA 3173-1] linux-5.10 security update | lists.debian.org text/html |
![]() |
kernel/git/torvalds/linux.git - Linux kernel source tree | git.kernel.org text/html |
![]() |
CVE-2022-41222 Linux Kernel Vulnerability in NetApp Products | NetApp Product Security | security.netapp.com text/html |
![]() |
Related QID Numbers
- 160476 Oracle Enterprise Linux Security Update for kernel (ELSA-2023-0832)
- 181065 Debian Security Update for linux (CVE-2022-41222)
- 181190 Debian Security Update for linux-5.10 (DLA 3173-1)
- 199029 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-5728-1)
- 199037 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-5728-2)
- 199051 Ubuntu Security Notification for Linux kernel (GCP) Vulnerabilities (USN-5728-3)
- 241202 Red Hat Update for kpatch-patch (RHSA-2023:0839)
- 241204 Red Hat Update for kernel-rt (RHSA-2023:0854)
- 241209 Red Hat Update for kernel (RHSA-2023:0832)
- 241252 Red Hat Update for kernel (RHSA-2023:1130)
- 241254 Red Hat Update for kpatch-patch (RHSA-2023:1192)
- 354081 Amazon Linux Security Advisory for kernel : ALAS2KERNEL-5.4-2022-036
- 354084 Amazon Linux Security Advisory for kernel : ALAS2KERNEL-5.10-2022-020
- 377891 Alibaba Cloud Linux Security Update for cloud-kernel (ALINUX3-SA-2023:0002)
- 610466 Google Android Devices February 2023 Security Patch Missing
- 610472 Google Android March 2023 Security Patch Missing for Samsung
- 752708 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:3704-1)
- 752724 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:3775-1)
- 753119 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 15 for SLE 15 SP3) (SUSE-SU-2022:3657-1)
- 753143 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 24 for SLE 15 SP3) (SUSE-SU-2022:3606-1)
- 753352 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 29 for SLE 15 SP2) (SUSE-SU-2022:3648-1)
- 753370 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:3609-1)
- 753374 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:3809-1)
- 753394 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 30 for SLE 15 SP2) (SUSE-SU-2022:3607-1)
- 904033 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (10987)
- 904105 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (10987-1)
- 906122 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (10987-2)
- 940926 AlmaLinux Security Update for kernel (ALSA-2023:0832)
- 940936 AlmaLinux Security Update for kernel-rt (ALSA-2023:0854)
- 960651 Rocky Linux Security Update for kernel (RLSA-2023:0832)
- 960656 Rocky Linux Security Update for kernel-rt (RLSA-2023:0854)
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Operating System | Debian | Debian Linux | 10.0 | All | All | All |
Operating System | Linux | Linux Kernel | All | All | All | All |
- cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*:
- cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-41222 : mm/mremap.c in the #Linux #kernel before 5.13.3 has a use-after-free via a stale TLB because an rm… twitter.com/i/web/status/1… | 2022-09-21 08:02:20 |
![]() |
New Vulnerability: CVE-2022-41222 #InceptusSecure #UnderOurProtection | 2022-09-21 10:20:04 |
![]() |
Git - CVE-2022-41222: cdn.kernel.org/pub/linux/kern… | 2022-09-21 11:01:23 |
![]() |
CVE-2022-41222 | 2022-09-21 08:38:57 |
![]() |
MS-ISAC CYBERSECURITY ADVISORY - Multiple Vulnerabilities in Google Android OS Could Allow for Privilege Escalation - PATCH: NOW | 2023-02-07 12:52:13 |