ID:9081 - Exploit for Double Free in Linux kernel - CVE-2022-2588

 
Main Vulnerability Database Exploits ID:9081 - Exploit for Double Free in Linux kernel - CVE-2022-2588

ID:9081 - Exploit for Double Free in Linux kernel - CVE-2022-2588

Published: May 21, 2023


Vulnerability identifier: #VU66397
Vulnerability risk: Low
CVE-ID: CVE-2022-2588
CWE-ID: CWE-415
Exploitation vector: Local access
Vulnerable software:
Linux kernel

Link to public exploit:


Vulnerability description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a double free error within the network packet scheduler implementation in the route4_change() function in Linux kernel when removing all references to a route filter before freeing it. A local user can run a specially crafted program to crash the kernel or execute arbitrary code.


Remediation

Install updates from vendor's website.