CVE-2022-1043 is a critical flaw in the Linux kernel's io_uring implementation, affecting Linux systems. This vulnerability allows a local attacker to corrupt system memory, leading to system crashes or privilege escalation. With a CVSS score of 8.8 (High), it presents a significant risk due to its low attack complexity and high impact on confidentiality, integrity, and availability. While not currently on the CISA KEV catalog, a Metasploit module exists for exploitation, indicating readily available exploit code. Despite this, community discussion and media coverage remain minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.10.51, < 5.10.61CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.11, < 5.13.13CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2022-1043
Sep 13, 2022A flaw was found in the Linux kernel’s io_uring implementation. This flaw allows an attacker with a local account to corrupt system memory crash the system or escalate privileges.
Aug 9, 2022kernel: Linux Kernel io_uring Use-After-Free Privilege Escalation Vulnerability
Feb 16, 2022