In the Linux kernel before 5.17.3, fs/iouring.c has a use-after-free due to a race condition in iouring timeouts. This can be triggered by a local user who has no access to any user namespace; however, the race condition perhaps can only be exploited infrequently.
[
{
"deprecated": false,
"target": {
"function": "io_timeout_prep",
"file": "fs/io_uring.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@e677edbcabee849bfdd43f1602bccbecf736a646",
"digest": {
"function_hash": "120097581135660455090247445570937777402",
"length": 1487.0
},
"signature_type": "Function",
"signature_version": "v1",
"id": "CVE-2022-29582-10ea7f67"
},
{
"deprecated": false,
"target": {
"file": "fs/io_uring.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@e677edbcabee849bfdd43f1602bccbecf736a646",
"digest": {
"line_hashes": [
"239890091910144256809410792987087923277",
"229201634306151408234757063363009339924",
"264816652838143543180705032960683796613",
"133843755877895727003324590807491966166",
"321905494055124281369865583953105597804",
"23657515125731489827201675979370554841",
"104285536753074518661356789773234767091",
"36068795037626440509808809136235567104",
"9373411352586735479019573266403788983",
"114763145292153712131505117664994001068",
"32125398790148285527765954021142472167",
"137392363159202028104486802178621546117",
"108538661192095818802606830057010038320",
"218641106355221646718237125060673688775",
"84516093268470079769497224275218809151",
"339885448005691394610368920873247310626"
],
"threshold": 0.9
},
"signature_type": "Line",
"signature_version": "v1",
"id": "CVE-2022-29582-ff4b1f92"
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-29582.json"