CVE-2022-2585
It was discovered that when exec'ing from a non-leader thread, armed POSIX CPU timers would be left on a list but freed, leading to a use-after-free.
- Affected products
- Alt Linux, Almalinux, Astra Linux, Linuxmint, Linux Kernel, Red Hat, Red Os, Rocky Linux
- Linux Linux Kernel
- < 5.10.137, 5.15.61, 5.18.18, 5.19.2
- CVSS 3.1
- 7.8 HIGH
- EPSS
- 1.3% (68th percentile)
- Weakness
- CWE-416
- NVD status
- Modified
- Published
- 2024-01-08
CVE-2022-2585 at NVD
5 known exploits for CVE-2022-2585
Proof-of-concept code and exploit modules indexed by Sploitus