kernel/ucount.c in the Linux kernel 5.14 through 5.16.4, when unprivileged user namespaces are enabled, allows a use-after-free and privilege escalation because a ucounts object can outlive its namespace.
References
Link | Resource |
---|---|
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=f9d87929d451d3e649699d0f1d74f71f77ad38f5 | Mailing List Patch Vendor Advisory |
https://github.com/torvalds/linux/commit/f9d87929d451d3e649699d0f1d74f71f77ad38f5 | Patch Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HSR3AI2IQGRKZCHNKF6S25JGDKUEAWWL/ | Mailing List |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VVSZKUJAZ2VN6LJ35J2B6YD6BOPQTU3B/ | Mailing List |
https://security.netapp.com/advisory/ntap-20220221-0001/ | Third Party Advisory |
https://www.openwall.com/lists/oss-security/2022/01/29/1 | Exploit Mailing List Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2022-01-29T21:33:55
Updated: 2022-02-21T09:06:43
Reserved: 2022-01-29T00:00:00
Link: CVE-2022-24122
JSON object: View
NVD Information
Status : Analyzed
Published: 2022-01-29T22:15:07.487
Modified: 2023-12-28T16:04:30.003
Link: CVE-2022-24122
JSON object: View
Redhat Information
No data.
CWE