{"schema_version":"1.9.0","id":"CVE-2022-2318","published":"2022-07-06T00:00:00Z","modified":"2026-08-12T03:51:12.675766531Z","related":["SUSE-SU-2022:2377-1","SUSE-SU-2022:2382-1","SUSE-SU-2022:2393-1","SUSE-SU-2022:2407-1","SUSE-SU-2022:2411-1","SUSE-SU-2022:2520-1","SUSE-SU-2022:2615-1","SUSE-SU-2022:2629-1","SUSE-SU-2022:2721-1","SUSE-SU-2022:2741-1","SUSE-SU-2022:2809-1","SUSE-SU-2022:2840-1","SUSE-SU-2022:2875-1","SUSE-SU-2022:2875-2","SUSE-SU-2022:2892-1","SUSE-SU-2022:2892-2","SUSE-SU-2023:0416-1"],"details":"There are use-after-free vulnerabilities caused by timer handler in net/rose/rose_timer.c of linux that allow attackers to crash linux kernel without any privileges.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/torvalds/linux","events":[{"introduced":"88084a3df1672e131ddc1b4e39eeacfd39864acf"},{"last_affected":"88084a3df1672e131ddc1b4e39eeacfd39864acf"}],"database_specific":{"extracted_events":[{"introduced":"Linux Kernel version prior to kernel 5.19 rc5"},{"last_affected":"Linux Kernel version prior to kernel 5.19 rc5"}],"source":"AFFECTED_FIELD"}}],"versions":["Linux Kernel version prior to kernel 5.19 rc5","v5.19-rc5"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-2318.json"}}],"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/2xxx/CVE-2022-2318.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-2318"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20230120-0001/"},{"type":"ADVISORY","url":"https://www.debian.org/security/2022/dsa-5191"},{"type":"FIX","url":"https://github.com/torvalds/linux/commit/9cc02ede696272c5271a401e4f27c262359bc2f6"},{"type":"ARTICLE","url":"https://lists.debian.org/debian-lts-announce/2022/10/msg00000.html"}],"database_specific":{"cna_assigner":"redhat","cwe_ids":["CWE-416"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/2xxx/CVE-2022-2318.json"}}