#VU64263 Use-after-free in Linux kernel - CVE-2022-1974
Published: June 14, 2022
Linux kernel
Linux Foundation
Description
The vulnerability allows a local privileged user to escalate privileges on the system.
The vulnerability exists due to a use-after-free error in the Linux kernel's NFC core functionality due to a race condition between kobject creation and delete. A local attacker with CAP_NET_ADMIN privilege can leak kernel information and escalate privileges on the system.