Skip to content

kernel CVE-2022-3176

Moderate
rpkelly published GHSA-rph4-chmh-mwx8 Jan 27, 2023

Package

kernel-5.15 (bottlerocket)

Affected versions

< 1.12.0

Patched versions

1.12.0

Description

A use-after-free flaw was found in io_uring in the Linux kernel. This flaw allows a local user to trigger the issue if a signalfd or binder fd is polled with the io_uring poll due to a lack of io_uring POLLFREE handling.

Severity

Moderate

CVE ID

CVE-2022-3176

Weaknesses

No CWEs