Use-after-free Vulnerability in Ubuntu POSIX CPU Timers
CVE-2022-2585
5.3MEDIUM
What is CVE-2022-2585?
A vulnerability exists in Ubuntu that occurs when executing from a non-leader thread. This issue causes armed POSIX CPU timers to be left on a list while being freed, resulting in a potential use-after-free situation. This flaw may lead to unintended behavior in the system, including possible crashes or arbitrary code execution if exploited. Immediate action and patching are essential to mitigate the risks associated with this vulnerability.
Affected Version(s)
linux Linux 0 < 6.0~rc1