A flaw in the Linux kernel's implementation of RDMA communications manager listener code allowed an attacker with local access to setup a socket to listen on a high port allowing for a list element to be used after free. Given the ability to execute code, a local attacker could leverage this use-after-free to crash the system or possibly escalate privileges on the system.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade kernel-tools-libs-devel | May 4, 2022 | Apr 26, 2022 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Aug 24, 2022 |
| Centos_linux | — | Upgrade kpatch-patch-3_10_0-1160_41_1-debuginfoUpgrade kpatch-patch-3_10_0-1160_36_2-debuginfoUpgrade kpatch-patch-4_18_0-348_7_1-debugsourceUpgrade kpatch-patch-4_18_0-348_20_1-debugsourceUpgrade kpatch-patch-4_18_0-348_2_1-debuginfoUpgrade kpatch-patch-4_18_0-348_2_1-debugsourceUpgrade kpatch-patch-3_10_0-1160_45_1Upgrade kpatch-patch-3_10_0-1160_49_1Upgrade kpatch-patch-4_18_0-348_12_2-debuginfoUpgrade kpatch-patch-3_10_0-1160_41_1Upgrade kernel-rtUpgrade kpatch-patch-3_10_0-1160_45_1-debuginfoUpgrade kpatch-patch-4_18_0-348_7_1-debuginfoUpgrade kpatch-patch-3_10_0-1160_42_2-debuginfoUpgrade kpatch-patch-3_10_0-1160_59_1-debuginfoUpgrade kpatch-patch-3_10_0-1160_25_1Upgrade kpatch-patch-4_18_0-348_2_1Upgrade kpatch-patch-4_18_0-348_12_2Upgrade kpatch-patch-3_10_0-1160_59_1Upgrade kpatch-patch-3_10_0-1160_49_1-debuginfoUpgrade kernelUpgrade kpatch-patch-3_10_0-1160_24_1-debuginfoUpgrade kpatch-patch-3_10_0-1160_53_1-debuginfoUpgrade kpatch-patch-3_10_0-1160_36_2Upgrade kpatch-patch-4_18_0-348Upgrade kpatch-patch-4_18_0-348-debugsourceUpgrade kpatch-patch-4_18_0-348-debuginfoUpgrade kpatch-patch-3_10_0-1160_53_1Upgrade kpatch-patch-3_10_0-1160_42_2Upgrade kpatch-patch-3_10_0-1160_31_1-debuginfoUpgrade kpatch-patch-4_18_0-348_20_1-debuginfoUpgrade kpatch-patch-4_18_0-348_20_1Upgrade kpatch-patch-3_10_0-1160_31_1Upgrade kpatch-patch-4_18_0-348_7_1Upgrade kpatch-patch-3_10_0-1160_24_1Upgrade kpatch-patch-3_10_0-1160_25_1-debuginfoUpgrade kpatch-patch-4_18_0-348_12_2-debugsource | Apr 6, 2022 | Apr 5, 2022 |
| Debian | — | Upgrade linux | Jul 30, 2024 | Aug 24, 2022 |
| Oracle_linux | — | Upgrade kernel | Apr 6, 2022 | Oct 4, 2021 |
| Redhat_linux | — | Upgrade kernelNo solution existsUpgrade kernel-rt | Feb 23, 2022 | Feb 22, 2022 |
| Rocky_linux | — | Upgrade kernel-rt-debug-debuginfoUpgrade kernel-debug-modules-extraUpgrade kernel-rt-develUpgrade perfUpgrade kernel-toolsUpgrade kernel-rt-debugUpgrade kernel-rt-modules-extraUpgrade kernel-develUpgrade bpftool-debuginfoUpgrade kernel-debug-debuginfoUpgrade bpftoolUpgrade kernel-rt-modulesUpgrade kernel-tools-libsUpgrade kernel-tools-libs-develUpgrade kernel-rt-debug-coreUpgrade python3-perf-debuginfoUpgrade kernel-rt-kvmUpgrade kernel-rtUpgrade kernel-rt-debuginfoUpgrade kernel-debugUpgrade kernel-cross-headersUpgrade kernel-headersUpgrade kernel-rt-debug-modulesUpgrade kernel-rt-debuginfo-common-x86_64Upgrade kernel-rt-coreUpgrade kernel-modulesUpgrade kernelUpgrade kernel-rt-debug-develUpgrade kernel-debuginfoUpgrade python3-perfUpgrade kernel-tools-debuginfoUpgrade kernel-debug-modulesUpgrade kernel-modules-extraUpgrade kernel-coreUpgrade kernel-debug-develUpgrade kernel-debuginfo-common-x86_64Upgrade perf-debuginfoUpgrade kernel-rt-debug-modules-extraUpgrade kernel-debug-core | Mar 5, 2024 | Aug 24, 2022 |
| Suse | — | Upgrade kernel-livepatch-5_3_18-59_27-defaultUpgrade kernel-livepatch-5_3_18-59_10-defaultUpgrade kernel-livepatch-5_3_18-59_19-defaultUpgrade kernel-livepatch-5_3_18-59_24-defaultUpgrade kernel-livepatch-5_3_18-59_5-defaultUpgrade kernel-livepatch-5_3_18-57-defaultUpgrade kernel-livepatch-5_3_18-59_16-defaultUpgrade kernel-livepatch-5_3_18-59_13-default | Feb 4, 2022 | Feb 1, 2022 |
| Ubuntu | — | Upgrade linux-oem-5.14Upgrade linux-kvmUpgrade linux-oem-5.10Upgrade linux-awsUpgrade linux-aws-5.11Upgrade linux-gcp-5.11Upgrade linux-oracleUpgrade linux-azureUpgrade linux-azure-5.11Upgrade linux-riscv-5.11Upgrade linux-oracle-5.11Upgrade linux-oem-5.13Upgrade linuxUpgrade linux-raspiUpgrade linux-riscvUpgrade linux-gcpUpgrade linux-hwe-5.13 | Nov 19, 2024 | Aug 24, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub