kernel CVE-2022-2585
Package
kernel-5.10
(bottlerocket)
Affected versions
< 1.12.0
Patched versions
1.12.0
kernel-5.15
(bottlerocket)
< 1.12.0
1.12.0
A use-after-free flaw was found in the Linux kernel's POSIX CPU timers functionality in the way a user creates and then deletes the timer in the non-leader thread of the program. This flaw allows a local user to crash or potentially escalate their privileges on the system.