CVE-2022-2327High· 7.5▾ Twilightio_uring use work_flags to determine which identity need to grab from the calling process to make sure it is consistent with the calling process when executing IORING_OP. Some operations are missing some types, which can lead to incorrec…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
io_uring use work_flags to determine which identity need to grab from the calling process to make sure it is consistent with the calling process when executing IORING_OP. Some operations are missing some types, which can lead to incorrect reference counts which can then lead to a double free. We recommend upgrading the kernel past commit df3f3bb5059d20ef094d6b2f0256c4bf4127a859
h300s_firmwareh500s_firmwareh700s_firmwareh410s_firmwareh410c_firmwarelinux_kernel < 5.10.125linux_kernel >= 5.11, < 5.12Upgrade past the affected range:
linux_kernel 5.12Connected by shared product, vendor, weakness, or advisory.
CVE-2024-1086High· 7.8A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the hook verdict, …
CVE-2021-23134High· 7.8Use After Free vulnerability in nfc sockets in the Linux Kernel before 5.12.4 allows local attackers to elevate their privileges
CVE-2022-1199High· 7.5A flaw was found in the Linux kernel
CVE-2022-4696High· 7.8There exists a use-after-free vulnerability in the Linux kernel through io_uring and the IORING_OP_SPLICE operation
CVE-2021-28691High· 7.8Guest triggered use-after-free in Linux xen-netback A malicious or buggy network PV frontend can force Linux netback to disable the interface and terminate the receive kernel thread associated with queue 0 in response to the frontend sen…
CVE-2021-3483High· 7.8A flaw was found in the Nosy driver in the Linux kernel