Risk | Low |
Patch available | NO |
Number of vulnerabilities | 1 |
CVE-ID | CVE-2022-1280 |
CWE-ID | CWE-416 |
Exploitation vector | Local |
Public exploit | N/A |
Vulnerable software Subscribe |
Linux kernel Operating systems & Components / Operating system |
Vendor | Linux Foundation |
Security Bulletin
This security bulletin contains one low risk vulnerability.
EUVDB-ID: #VU62358
Risk: Low
CVSSv3.1:
CVE-ID: CVE-2022-1280
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to a use-after-free error within the drm_lease_held() function in drivers/gpu/drm/drm_lease.c in the Linux kernel. A local user can run a specially crafted program to trigger a use-after-free error and crash the kernel or gain access to sensitive information.
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.
Vulnerable software versionsLinux kernel: All versions
Fixed software versionsCPE2.3 External links
http://bugzilla.redhat.com/show_bug.cgi?id=2071022
http://www.openwall.com/lists/oss-security/2022/04/12/3
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?