HIGH 7.0 Microsoft

CVE-2022-2961

A use-after-free flaw was found in the Linux kernel’s PLP Rose functionality in the way a user triggers a race condition by calling bind while simultaneously triggering the rose_bind() function. This flaw allows a local user to crash or potentially escalate their privileges on the system.

Microsoft Security Update 2022-Aug: A use-after-free flaw was found in the Linux kernel’s PLP Rose functionality in the way a user triggers a race condition by calling bind while simultaneously triggering the rose_bind() function. This flaw allows a local user to crash or potentially escalate their privileges on the system.

Affected Products

References

Published: 2022-08-09 · Source: Microsoft · Feed updated: 2026-09-03
This high severity vulnerability with a CVSS score of 7.0 was published on 2022-08-09 via Microsoft. Affected: cm1 kernel 5.10.189.1-1 on CBL Mariner 1.0, cbl2 kernel 5.15.167.1-2 on CBL Mariner 2.0.
vulnfeed aggregates 9119 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.