A use-after-free exists in the Linux Kernel in tc_new_tfilter that could allow a local attacker to gain privilege escalation. The exploit requires unprivileged user namespaces. We recommend upgrading…
High CVSS 7.8
Summary
A use-after-free exists in the Linux Kernel in tc_new_tfilter that could allow a local attacker to gain privilege escalation. The exploit requires unprivileged user namespaces. We recommend upgrading past commit 04c2a47ffb13c29778e2a14e414ad4cb5a5db4b5
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
- :
- :
- :
- :
- :
- :
- :
- :
- :
- :
- :
Lint boundary warnings (6)
The following non-blocking warnings were raised during the lint phase of this triage (e.g. reference URLs not yet on the allowlist). They do not affect entry usability and are disclosed for transparency (see DR-002).
-
REF_URL_NOT_ALLOWLISTEDurl not in allowlist: http://packetstormsecurity.com/files/167386/Kernel-Live-Patch-Security-Notice-LSN-0086-1.html -
REF_URL_NOT_ALLOWLISTEDurl not in allowlist: https://kernel.dance/#04c2a47ffb13c29778e2a14e414ad4cb5a5db4b5 -
REF_URL_NOT_ALLOWLISTEDurl not in allowlist: https://syzkaller.appspot.com/bug?id=2212474c958978ab86525fe6832ac8102c309ffc -
REF_URL_NOT_ALLOWLISTEDurl not in allowlist: http://packetstormsecurity.com/files/167386/Kernel-Live-Patch-Security-Notice-LSN-0086-1.html -
REF_URL_NOT_ALLOWLISTEDurl not in allowlist: https://kernel.dance/#04c2a47ffb13c29778e2a14e414ad4cb5a5db4b5 -
REF_URL_NOT_ALLOWLISTEDurl not in allowlist: https://syzkaller.appspot.com/bug?id=2212474c958978ab86525fe6832ac8102c309ffc
Sources
- NVD DATABASE
Original Links
- http://packetstormsecurity.com/files/167386/Kernel-Live-Patch-Security-Notice-LSN-0086-1.html Third Party Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=04c2a47ffb13c29778e2a14e414ad4cb5a5db4b5 Patch
- https://kernel.dance/#04c2a47ffb13c29778e2a14e414ad4cb5a5db4b5 Exploit
- https://security.netapp.com/advisory/ntap-20220506-0007/ Third Party Advisory
- https://syzkaller.appspot.com/bug?id=2212474c958978ab86525fe6832ac8102c309ffc Exploit
- http://packetstormsecurity.com/files/167386/Kernel-Live-Patch-Security-Notice-LSN-0086-1.html Third Party Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=04c2a47ffb13c29778e2a14e414ad4cb5a5db4b5 Patch
- https://kernel.dance/#04c2a47ffb13c29778e2a14e414ad4cb5a5db4b5 Exploit
- https://security.netapp.com/advisory/ntap-20220506-0007/ Third Party Advisory
- https://syzkaller.appspot.com/bug?id=2212474c958978ab86525fe6832ac8102c309ffc Exploit
Timeline
- nvd_ingest NVD