CVE-2022-41849
- EPSS 0.02%
- Veröffentlicht 30.09.2022 06:15:12
- Zuletzt bearbeitet 21.11.2024 07:23:56
drivers/video/fbdev/smscufx.c in the Linux kernel through 5.19.12 has a race condition and resultant use-after-free if a physically proximate attacker removes a USB device while calling open(), aka a race condition between ufx_ops_open and ufx_usb_di...
CVE-2022-41850
- EPSS 0.04%
- Veröffentlicht 30.09.2022 06:15:12
- Zuletzt bearbeitet 21.11.2024 07:23:56
roccat_report_event in drivers/hid/hid-roccat.c in the Linux kernel through 5.19.12 has a race condition and resultant use-after-free in certain situations where a report is received while copying a report->value is in progress.
CVE-2022-41848
- EPSS 0.03%
- Veröffentlicht 30.09.2022 06:15:11
- Zuletzt bearbeitet 20.05.2025 20:15:27
drivers/char/pcmcia/synclink_cs.c in the Linux kernel through 5.19.12 has a race condition and resultant use-after-free if a physically proximate attacker removes a PCMCIA device while calling ioctl, aka a race condition between mgslpc_ioctl and mgsl...
CVE-2022-3303
- EPSS 0.02%
- Veröffentlicht 27.09.2022 23:15:15
- Zuletzt bearbeitet 21.05.2025 16:15:28
A race condition flaw was found in the Linux kernel sound subsystem due to improper locking. It could lead to a NULL pointer dereference while handling the SNDCTL_DSP_SYNC ioctl. A privileged local user (root or member of the audio group) could use t...
CVE-2022-41218
- EPSS 0.49%
- Veröffentlicht 21.09.2022 07:15:08
- Zuletzt bearbeitet 28.05.2025 16:15:28
In drivers/media/dvb-core/dmxdev.c in the Linux kernel through 5.19.10, there is a use-after-free caused by refcount races, affecting dvb_demux_open and dvb_dmxdev_release.
CVE-2022-3239
- EPSS 0.03%
- Veröffentlicht 19.09.2022 20:15:12
- Zuletzt bearbeitet 21.11.2024 07:19:07
A flaw use after free in the Linux kernel video4linux driver was found in the way user triggers em28xx_usb_probe() for the Empia 28xx based TV cards. A local user could use this flaw to crash the system or potentially escalate their privileges on the...
CVE-2022-40768
- EPSS 0.02%
- Veröffentlicht 18.09.2022 05:15:08
- Zuletzt bearbeitet 21.11.2024 07:22:01
drivers/scsi/stex.c in the Linux kernel through 5.19.9 allows local users to obtain sensitive information from kernel memory because stex_queuecommand_lck lacks a memset for the PASSTHRU_CMD case.
CVE-2022-36402
- EPSS 0.05%
- Veröffentlicht 16.09.2022 17:15:10
- Zuletzt bearbeitet 21.11.2024 07:12:57
An integer overflow vulnerability was found in vmwgfx driver in drivers/gpu/vmxgfx/vmxgfx_execbuf.c in GPU component of Linux kernel with device file '/dev/dri/renderD128 (or Dxxx)'. This flaw allows a local attacker with a user account on the system...
CVE-2022-3176
- EPSS 0.02%
- Veröffentlicht 16.09.2022 14:15:09
- Zuletzt bearbeitet 21.11.2024 07:18:58
There exists a use-after-free in io_uring in the Linux kernel. Signalfd_poll() and binder_poll() use a waitqueue whose lifetime is the current task. It will send a POLLFREE notification to all waiters before the queue is freed. Unfortunately, the io_...
CVE-2022-2977
- EPSS 0.02%
- Veröffentlicht 14.09.2022 21:15:10
- Zuletzt bearbeitet 21.11.2024 07:02:01
A flaw was found in the Linux kernel implementation of proxied virtualized TPM devices. On a system where virtualized TPM devices are configured (this is not the default) a local attacker can create a use-after-free and create a situation where it ma...