UBUNTU-CVE-2022-1055
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-1055
UBUNTU-CVE-2022-1055
Summary:
Details: A use-after-free exists in the Linux Kernel in tc_new_tfilter that could allow a local attacker to gain privilege escalation. The exploit requires unprivileged user namespaces. We recommend upgrading past commit 04c2a47ffb13c29778e2a14e414ad4cb5a5db4b5
References: https://ubuntu.com/security/CVE-2022-1055, https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=04c2a47ffb13c29778e2a14e414ad4cb5a5db4b5, https://syzkaller.appspot.com/bug?id=2212474c958978ab86525fe6832ac8102c309ffc, https://ubuntu.com/security/notices/USN-5358-1, https://ubuntu.com/security/notices/USN-5358-2, https://ubuntu.com/security/notices/USN-5368-1, https://ubuntu.com/security/notices/USN-5377-1, https://www.cve.org/CVERecord?id=CVE-2022-1055
Affected packages
Package
Name: linux-hwe-edge
Purl: pkg:deb/ubuntu/linux-hwe-edge?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
