AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2022-0646

HIGH · CVSS 7.8 EPSS 0.34%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2022-02-18 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2022-0646
Severity
HIGH
CVSS
7.8
EPSS
0.34%
Linux

Original NVD Description

A flaw use after free in the Linux kernel Management Component Transport Protocol (MCTP) subsystem was found in the way user triggers cancel_work_sync after the unregister_netdev during removing device. A local user could use this flaw to crash the system or escalate their privileges on the system. It is actual from Linux Kernel 5.17-rc1 (when mctp-serial.c introduced) till 5.17-rc5.