CVE-2022-1729
kernel: race condition in perf_event_open leads to privilege escalation
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A race condition was found the Linux kernel in perf_event_open() which can be exploited by an unprivileged user to gain root privileges. The bug allows to build several exploit primitives such as kernel address information leak, arbitrary execution, etc.
Se ha encontrado una condición de carrera en el kernel de Linux en la función perf_event_open() que puede ser explotada por un usuario no privilegiado para conseguir privilegios de root. El bug permite construir varias primitivas de explotación como un filtrado de información de direcciones del kernel, una ejecución arbitraria, etc
A use-after-free flaw was found in the Linux kernel’s performance events functionality. A user triggers a race condition in setting up performance monitoring between the leading PERF_TYPE_TRACEPOINT and sub PERF_EVENT_HARDWARE plus the PERF_EVENT_SOFTWARE using the perf_event_open() function with these three types. This flaw allows a local user to crash the system.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-05-16 CVE Reserved
- 2022-06-22 CVE Published
- 2024-03-24 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
- CWE-366: Race Condition within a Thread
CAPEC
References (5)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://access.redhat.com/security/cve/CVE-2022-1729 | 2022-09-28 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2086753 | 2022-09-28 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 3.2.85 < 3.3 Search vendor "Linux" for product "Linux Kernel" and version " >= 3.2.85 < 3.3" | - |
Affected
| ||||||
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 3.16.40 < 3.17 Search vendor "Linux" for product "Linux Kernel" and version " >= 3.16.40 < 3.17" | - |
Affected
| ||||||
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 3.18.54 < 3.19 Search vendor "Linux" for product "Linux Kernel" and version " >= 3.18.54 < 3.19" | - |
Affected
| ||||||
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 4.0.0 < 4.9.316 Search vendor "Linux" for product "Linux Kernel" and version " >= 4.0.0 < 4.9.316" | - |
Affected
| ||||||
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 4.10 < 4.14.281 Search vendor "Linux" for product "Linux Kernel" and version " >= 4.10 < 4.14.281" | - |
Affected
| ||||||
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 4.15 < 4.19.245 Search vendor "Linux" for product "Linux Kernel" and version " >= 4.15 < 4.19.245" | - |
Affected
| ||||||
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 4.20 < 5.4.196 Search vendor "Linux" for product "Linux Kernel" and version " >= 4.20 < 5.4.196" | - |
Affected
| ||||||
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 5.5.0 < 5.10.118 Search vendor "Linux" for product "Linux Kernel" and version " >= 5.5.0 < 5.10.118" | - |
Affected
| ||||||
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 5.11 < 5.15.42 Search vendor "Linux" for product "Linux Kernel" and version " >= 5.11 < 5.15.42" | - |
Affected
| ||||||
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 5.16 < 5.17.10 Search vendor "Linux" for product "Linux Kernel" and version " >= 5.16 < 5.17.10" | - |
Affected
| ||||||
Netapp Search vendor "Netapp" | Hci Baseboard Management Controller Search vendor "Netapp" for product "Hci Baseboard Management Controller" | h300s Search vendor "Netapp" for product "Hci Baseboard Management Controller" and version "h300s" | - |
Affected
| ||||||
Netapp Search vendor "Netapp" | Hci Baseboard Management Controller Search vendor "Netapp" for product "Hci Baseboard Management Controller" | h410s Search vendor "Netapp" for product "Hci Baseboard Management Controller" and version "h410s" | - |
Affected
| ||||||
Netapp Search vendor "Netapp" | Hci Baseboard Management Controller Search vendor "Netapp" for product "Hci Baseboard Management Controller" | h500s Search vendor "Netapp" for product "Hci Baseboard Management Controller" and version "h500s" | - |
Affected
| ||||||
Netapp Search vendor "Netapp" | Hci Baseboard Management Controller Search vendor "Netapp" for product "Hci Baseboard Management Controller" | h700s Search vendor "Netapp" for product "Hci Baseboard Management Controller" and version "h700s" | - |
Affected
|