Skip to content

kernel CVE-2022-28388

Moderate
arnaldo2792 published GHSA-97xg-3hrx-6h7x Jun 10, 2022

Package

kernel-5.10 (bottlerocket)

Affected versions

< 1.8.0

Patched versions

1.8.0

Description

It was discovered that the 8 Devices USB2CAN interface implementation in the Linux kernel did not properly handle certain error conditions, leading to a double-free. A local attacker could possibly use this to cause a denial of service via system crash.

Severity

Moderate

CVE ID

CVE-2022-28388

Weaknesses

No CWEs