CVE-2022-1055 is a use-after-free vulnerability in the Linux Kernel's tc_new_tfilter function, affecting various distributions including Canonical, Fedora, NetApp, and Red Hat. This high-severity flaw (CVSS 7.8) allows a local attacker to achieve privilege escalation, though it requires unprivileged user namespaces. While no public exploit code or active exploitation has been observed, and community discussion is minimal, upgrading to commit 04c2a47ffb13c29778e2a14e414ad4cb5a5db4b5 is recommended to mitigate the risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.1, < 5.17CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
5.17CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:5.17:-:*:*:*:*:*:* | ||
5.17CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:5.17:rc1:*:*:*:*:*:* | ||
5.17CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:5.17:rc2:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2022-1055
Dec 10, 2024Linux kernel container breakout and privilege escalation (CVE-2022-1055, CVE-2022-27666)
Nov 22, 2022Use after Free in tc_new_tfilter allowing for privilege escalation in Linux Kernel
Mar 8, 2022kernel: use-after-free in tc_new_tfilter() in net/sched/cls_api.c
Jan 31, 2022