kernel CVE-2022-28389
Package
kernel-5.10
(bottlerocket)
Affected versions
< 1.8.0
Patched versions
1.8.0
kernel-5.4
(bottlerocket)
< 1.8.0
1.8.0
It was discovered that the Microchip CAN BUS Analyzer interface implementation in the Linux kernel did not properly handle certain error conditions, leading to a double-free. A local attacker could possibly use this to cause a denial of service via system crash.