Skip to content

kernel CVE-2022-2978

High
rpkelly published GHSA-2r75-pvxx-p558 Jan 27, 2023

Package

kernel-5.10 (bottlerocket)

Affected versions

< 1.12.0

Patched versions

1.12.0
kernel-5.15 (bottlerocket)
< 1.12.0
1.12.0

Description

A use-after-free flaw was found in the Linux kernel NILFS file system in the way user triggers function security_inode_alloc to fail with following call to function nilfs_mdt_destroy. A local user could use this flaw to crash the system or potentially escalate their privileges on the system.

Severity

High

CVE ID

CVE-2022-2978

Weaknesses

No CWEs