Lucene search

K
ubuntucveUbuntu.comUB:CVE-2022-2318
HistoryJul 06, 2022 - 12:00 a.m.

CVE-2022-2318

2022-07-0600:00:00
ubuntu.com
ubuntu.com
33

4.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:N/I:N/A:C

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

0.0004 Low

EPSS

Percentile

5.1%

There are use-after-free vulnerabilities caused by timer handler in
net/rose/rose_timer.c of linux that allow attackers to crash linux kernel
without any privileges.

OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchlinux< 4.15.0-194.205UNKNOWN
ubuntu20.04noarchlinux< 5.4.0-128.144UNKNOWN
ubuntu22.04noarchlinux< 5.15.0-48.54UNKNOWN
ubuntu16.04noarchlinux< 4.4.0-239.273UNKNOWN
ubuntu18.04noarchlinux-aws< 4.15.0-1142.154UNKNOWN
ubuntu20.04noarchlinux-aws< 5.4.0-1086.93UNKNOWN
ubuntu22.04noarchlinux-aws< 5.15.0-1020.24UNKNOWN
ubuntu14.04noarchlinux-aws< 4.4.0-1117.123UNKNOWN
ubuntu16.04noarchlinux-aws< 4.4.0-1155.170UNKNOWN
ubuntu20.04noarchlinux-aws-5.15< 5.15.0-1020.24~20.04.1UNKNOWN
Rows per page:
1-10 of 631

References

4.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:N/I:N/A:C

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

0.0004 Low

EPSS

Percentile

5.1%