Back

HIGH

kernel: posix cpu timer use-after-free may lead to local privilege escalation

Published Jan 8, 2024

Description

It was discovered that when exec'ing from a non-leader thread, armed POSIX CPU timers would be left on a list but freed, leading to a use-after-free.

Affected products

Remediation

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Weaknesses (1)

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner canonical
Published Jan 8, 2024
Updated Sep 4, 2024
Reserved Jul 29, 2022
CISA Vulnrichment
Updated Apr 2, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Aug 9, 2022
ENISA EUVD
Assigner canonical
Published Jan 8, 2024
Updated Sep 4, 2024
Exploited since n/a
EUVD-2022-34834