CVE-2022-29581

Aliases:UBUNTU-CVE-2022-29581DEBIAN-CVE-2022-29581
Advisory lineage Upstream: 0 Downstream: 45
Modified
Published: 17 May 2022, 16:50
Last modified:21 Apr 2025, 13:53

Vulnerability Summary

Overall Risk (default)
medium
41/100
CVSS Score
7.8 HIGH
v3.1 (cve.org)
EPSS Score
0.93% LOW
1% probability +0.64%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

17 May 2022, 16:50
Published
Vulnerability first disclosed
21 Apr 2025, 13:53
Last Modified
Vulnerability information updated

Description

Improper Update of Reference Count vulnerability in net/sched of Linux Kernel allows local attacker to cause privilege escalation to root. This issue affects: Linux Kernel versions prior to 5.18; version 4.14 and later versions.

CVSS Metrics

  • v3.1HIGHScore: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • v2.0HIGHScore: 7.2AV:L/AC:L/Au:N/C:C/I:C/A:C

EPSS Trends

Current EPSS score: 0.93% Percentile: 59%

Techniques & Countermeasures

  • CWE-911Improper Update of Reference Count

    The product uses a reference count to manage a resource, but it does not update or incorrectly updates the reference count.

Affected Systems

  • canonicalubuntu_linux

    14.04 | 16.04 | 18.04 | 20.04 | 22.04

  • debianlinux

    < 5.10.113-1 | < 5.17.6-1 | < 5.17.6-1 | < 5.17.6-1

  • ubuntulinux

    < 4.15.0-180.189 | < 5.4.0-113.127 | < 5.15.0-33.34

  • ubuntulinux-aws

    < 4.15.0-1130.139 | < 5.4.0-1075.80 | < 5.15.0-1008.10

  • ubuntulinux-aws-5.0

    all

  • ubuntulinux-aws-5.11

    all

  • ubuntulinux-aws-5.13

    < 5.13.0-1025.27~20.04.1

  • ubuntulinux-aws-5.3

    all

  • ubuntulinux-aws-5.4

    < 5.4.0-1075.80~18.04.1

  • ubuntulinux-aws-5.8

    all

  • ubuntulinux-aws-fips

    < 4.15.0-2069.72 | all | < 5.4.0-1078.84+fips1

  • ubuntulinux-aws-hwe

    < 4.15.0-1130.139~16.04.1

  • ubuntulinux-azure

    < 4.15.0-1139.152~14.04.1 | < 4.15.0-1139.152~16.04.1 | all | < 5.4.0-1080.83 | < 5.15.0-1007.8

  • ubuntulinux-azure-4.15

    < 4.15.0-1139.152

  • ubuntulinux-azure-5.11

    all

  • ubuntulinux-azure-5.13

    < 5.13.0-1025.29~20.04.1

  • ubuntulinux-azure-5.3

    all

  • ubuntulinux-azure-5.4

    < 5.4.0-1080.83~18.04.2

  • ubuntulinux-azure-5.8

    all

  • ubuntulinux-azure-edge

    all

  • ubuntulinux-azure-fips

    < 4.15.0-2050.54 | all | < 5.4.0-1080.83+fips1

  • ubuntulinux-bluefield

    all | < 5.4.0-1036.39

  • ubuntulinux-dell300x

    < 4.15.0-1047.52

  • ubuntulinux-fips

    < 4.15.0-1087.96 | all | < 5.4.0-1051.57

  • ubuntulinux-gcp

    < 4.15.0-1124.138~16.04.1 | all | < 5.4.0-1075.80 | < 5.15.0-1005.8

  • ubuntulinux-gcp-4.15

    < 4.15.0-1124.138

  • ubuntulinux-gcp-5.11

    all

  • ubuntulinux-gcp-5.13

    < 5.13.0-1027.32~20.04.1

  • ubuntulinux-gcp-5.3

    all

  • ubuntulinux-gcp-5.4

    < 5.4.0-1075.80~18.04.1

  • ubuntulinux-gcp-5.8

    all

  • ubuntulinux-gcp-fips

    < 4.15.0-2034.37 | all | < 5.4.0-1075.80+fips1

  • ubuntulinux-gke

    < 5.4.0-1072.77 | < 5.15.0-1005.6

  • ubuntulinux-gke-4.15

    all

  • ubuntulinux-gke-5.4

    < 5.4.0-1072.77~18.04.1

  • ubuntulinux-gkeop

    < 5.4.0-1043.44

  • ubuntulinux-gkeop-5.4

    < 5.4.0-1043.44~18.04.1

  • ubuntulinux-hwe

    < 4.15.0-180.189~16.04.1 | all

  • ubuntulinux-hwe-5.11

    all

  • ubuntulinux-hwe-5.13

    < 5.13.0-44.49~20.04.1

  • ubuntulinux-hwe-5.4

    < 5.4.0-113.127~18.04.1

  • ubuntulinux-hwe-5.8

    all

  • ubuntulinux-hwe-edge

    all | all

  • ubuntulinux-ibm

    < 5.4.0-1023.25 | < 5.15.0-1004.4

  • ubuntulinux-ibm-5.4

    < 5.4.0-1023.25~18.04.1

  • ubuntulinux-intel-5.13

    all

  • ubuntulinux-intel-iot-realtime

    all

  • ubuntulinux-intel-iotg

    < 5.15.0-1008.11

  • ubuntulinux-intel-iotg-5.15

    < 5.15.0-1008.11~20.04.1

  • ubuntulinux-iot

    < 5.4.0-1004.6

Showing first 50 affected entries in server-rendered view.

References (15)