CVE-2022-24122

Related Vulnerabilities: CVE-2022-24122  

kernel/ucount.c in the Linux kernel 5.14 through 5.16.4, when unprivileged user namespaces are enabled, allows a use-after-free and privilege escalation because a ucounts object can outlive its namespace.

Description

The MITRE CVE dictionary describes this issue as:

kernel/ucount.c in the Linux kernel 5.14 through 5.16.4, when unprivileged user namespaces are enabled, allows a use-after-free and privilege escalation because a ucounts object can outlive its namespace.

Additional Information

  • Bugzilla 2048492: CVE-2022-24122 kernel: use-after-free and privilege escalation in kernel/ucount.c when unprivileged user namespaces are enabled
  • CWE-416: Use After Free
  • FAQ: Frequently asked questions about CVE-2022-24122