Skip to content

kernel CVE-2022-28390

Moderate
arnaldo2792 published GHSA-9q5w-2vg7-mx44 Jun 10, 2022

Package

kernel-5.10 (bottlerocket)

Affected versions

< 1.8.0

Patched versions

1.8.0
kernel-5.4 (bottlerocket)
< 1.8.0
1.8.0

Description

It was discovered that the EMS CAN/USB interface implementation in the Linux kernel contained a double-free vulnerability when handling certain error conditions. A local attacker could use this to cause a denial of service via memory exhaustion.

Severity

Moderate

CVE ID

CVE-2022-28390

Weaknesses

No CWEs