Skip to content

kernel CVE-2022-2318

Moderate
rpkelly published GHSA-mj6m-x92g-mcp8 Jul 29, 2022

Package

kernel-5.10 (bottlerocket)

Affected versions

< 1.9.0

Patched versions

1.9.0

Description

There are use-after-free vulnerabilities caused by timer handler in net/rose/rose_timer.c of linux that allow attackers to crash linux kernel without any privileges.

Severity

Moderate

CVE ID

CVE-2022-2318

Weaknesses

No CWEs