HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2022-1729

CVSS 7.0v3.1pub. 2022-09-01upd. 2024-11-21

A race condition was found the Linux kernel in perf_event_open() which can be exploited by an unprivileged user to gain root privileges. The bug allows to build several exploit primitives such as kernel address information leak, arbitrary execution, etc.

CVSS Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Linux Kernel

    OS
    Linux
    3.2.85 – 3.3 (excl.)3.16.40 – 3.17 (excl.)3.18.54 – 3.19 (excl.)4.0.0 – 4.9.316 (excl.)4.10 – 4.14.281 (excl.)4.15 – 4.19.245 (excl.)4.20 – 5.4.196 (excl.)5.5.0 – 5.10.118 (excl.)5.11 – 5.15.42 (excl.)5.16 – 5.17.10 (excl.)
  • Netapp Hci Baseboard Management Controller

    APP
    Netapp
    h300sh410sh500sh700s
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Race Condition
CWE
References

Related vulnerabilities

CVE-2025-10585CRITICAL9.8⚠ KEVPL ✓same product

Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty

CVE-2025-34028CRITICAL9.3⚠ KEVPL ✓same product

Commvault Command Center – nieuwierzytelniony RCE przez path traversal w ZIP

CVE-2022-47986CRITICAL9.8⚠ KEVPL ✓same product

RCE przez YAML deserialization w IBM Aspera Faspex

CVE-2022-22954CRITICAL9.8⚠ KEVPL ✓same product

RCE w VMware Workspace ONE Access i Identity Manager poprzez server-side template injection

CVE-2020-4006CRITICAL9.1⚠ KEVPL ✓same product

Command Injection w VMware Workspace One Access i Identity Manager