7.8
CVSSv3

CVE-2022-24122

Published: 29/01/2022 Updated: 28/12/2023
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 614
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

kernel/ucount.c in the Linux kernel 5.14 up to and including 5.16.4, when unprivileged user namespaces are enabled, allows a use-after-free and privilege escalation because a ucounts object can outlive its namespace.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

linux linux kernel

netapp h410c firmware -

netapp h300s firmware -

netapp h500s firmware -

netapp h700s firmware -

netapp h300e firmware -

netapp h500e firmware -

netapp h700e firmware -

netapp h410s firmware -

fedoraproject fedora 34

fedoraproject fedora 35

Vendor Advisories

Several security issues were fixed in the Linux kernel ...
kernel/ucountc in the Linux kernel 514 through 5164, when unprivileged user namespaces are enabled, allows a use-after-free and privilege escalation because a ucounts object can outlive its namespace ...

Mailing Lists

Hi, On Sat, Jan 29, 2022 at 08:07:27PM +0100, Mathias Krause wrote: This issue has been assigned CVE-2022-24122 by MITRE via cveformmitreorg/ Regards, Salvatore ...

Github Repositories

CVE-2022-24122 Proof of Concept

CVE-2022-24122 Simple Denial of Service using CVE-2022-24122 It works with 1 core system and it has ~80% probability of success with 2 cores