kernel CVE-2022-28390
Package
kernel-5.10
(bottlerocket)
Affected versions
< 1.8.0
Patched versions
1.8.0
kernel-5.4
(bottlerocket)
< 1.8.0
1.8.0
It was discovered that the EMS CAN/USB interface implementation in the Linux kernel contained a double-free vulnerability when handling certain error conditions. A local attacker could use this to cause a denial of service via memory exhaustion.