CVE-2022-2585
HIGH 7.8EPSS 1.3%
It was discovered that when exec'ing from a non-leader thread, armed POSIX CPU timers would be left on a list but freed, leading to a use-after-free.
- CVSS v3.1
- 7.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 5.3 MEDIUM
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H - EPSS
- 1.28% chance of exploitation in the next 30 days, 68th percentile
- Published
- 2024-01-08
- Updated
- 2024-09-04
Proof-of-concept exploits (3)
- greek0x0/2022-LPE-UAF9★ · 2022-09-01
- konoha279/2022-LPE-UAF5★ · 2022-08-23
- pirenga/2022-LPE-UAF6★ · 2022-08-23