linux, linux-aws, linux-aws-hwe, linux-aws-5.13, linux-azure, linux-azure-5.13, linux-azure-4.15, linux-gcp, linux-gcp-4.15, linux-gke, linux-hwe, linux-hwe-5.13, linux-ibm, linux-kvm, linux-lowlatency, linux-oracle, linux-raspi, linux-raspi2, linux-snapdragon vulnerabilities
Kyle Zeng discovered that the Network Queuing and Scheduling subsystem of the Linux kernel did not properly perform reference counting in some situations, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or execute arbitrary code. (CVE-2022-29581) Jann Horn discovered that the Linux kernel did not properly enforce seccomp restrictions in some situations. A local attacker could use this to bypass intended seccomp sandbox restrictions. (CVE-2022-30594)
02 / AFFECTED SOFTWARE
Affected packages
94 explicit affected versions
82 explicit affected versions
38 explicit affected versions
37 explicit affected versions
76 explicit affected versions
62 explicit affected versions
80 explicit affected versions
60 explicit affected versions
9 explicit affected versions
8 explicit affected versions
12 explicit affected versions
8 explicit affected versions
5 explicit affected versions
5 explicit affected versions
5 explicit affected versions
3 explicit affected versions
2 explicit affected versions
7 explicit affected versions
5 explicit affected versions
4 explicit affected versions
6 explicit affected versions
69 explicit affected versions
61 explicit affected versions
92 explicit affected versions
84 explicit affected versions
109 explicit affected versions
60 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Kyle Zeng discovered that the Network Queuing and Scheduling subsystem of the Linux kernel did not properly perform reference counting in some situations, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or execute arbitrary code. (CVE-2022-29581) Jann Horn discovered that the Linux kernel did not properly enforce seccomp restrictions in some situations. A local attacker could use this to bypass intended seccomp sandbox restrictions. (CVE-2022-30594)
05 / REFERENCES