CVE-2022-1011High· 7.8▾ MidnightPoC availableA use-after-free flaw was found in the Linux kernel’s FUSE filesystem in the way a user triggers write(). This flaw allows a local user to gain unauthorized access to data from the FUSE filesystem, resulting in privilege escalation.
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 42.9 · likelihood 0.2 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Aug 26.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.2%
1 GitHub repo
A use-after-free flaw was found in the Linux kernel’s FUSE filesystem in the way a user triggers write(). This flaw allows a local user to gain unauthorized access to data from the FUSE filesystem, resulting in privilege escalation.
linux_kernel >= 2.6.35, < 4.9.320linux_kernel >= 4.10, < 4.14.276linux_kernel >= 4.15, < 4.19.238linux_kernel >= 4.20, < 5.4.185linux_kernel >= 5.5, < 5.10.106linux_kernel >= 5.11, < 5.15.29linux_kernel >= 5.16, < 5.16.15linux_kernel = 5.17fedora = 34fedora = 35build_of_quarkus = 2.0developer_tools = 1.0enterprise_linux = 6.0enterprise_linux = 7.0enterprise_linux = 8.0enterprise_linux_eus = 8.6enterprise_linux_for_ibm_z_systems = 8.0enterprise_linux_for_ibm_z_systems_eus = 8.6enterprise_linux_for_power_little_endian = 8.0enterprise_linux_for_power_little_endian_eus = 8.6enterprise_linux_for_real_time = 8enterprise_linux_for_real_time_for_nfv = 8enterprise_linux_for_real_time_for_nfv_tus = 8.6enterprise_linux_for_real_time_tus = 8.6enterprise_linux_server_aus = 8.6enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 8.6enterprise_linux_server_tus = 8.6enterprise_linux_server_update_services_for_sap_solutions = 8.6virtualization_host = 4.0codeready_linux_builderh300s_firmwareh500s_firmwareh700s_firmwareh300e_firmwareh500e_firmwareh700e_firmwareh410s_firmwareh410c_firmwaredebian_linux = 9.0debian_linux = 10.0communications_cloud_native_core_binding_support_function = 22.1.3Upgrade past the affected range:
linux_kernel 5.16.15Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2022-1734High· 7.0A flaw in Linux Kernel found in nfcmrvl_nci_unregister_dev() in drivers/nfc/nfcmrvl/main.c can lead to use after free both read or write when non synchronized between cleanup routine and firmware download routine.
CVE-2022-26485High· 8.8Removing an XSLT parameter during processing could have lead to an exploitable use-after-free
CVE-2022-2586Medium· 5.3It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that table was deleted.
CVE-2018-15982High· 7.8Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability
CVE-2021-26411High· 8.8Internet Explorer Memory Corruption Vulnerability
CVE-2020-3992Critical· 9.8OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after-free issue