CVE-2022-2585: Canonical Ubuntu Linux
High severity, CVSS 7.8. EPSS: 1.3% chance of exploitation in the next 30 days.
It was discovered that when exec'ing from a non-leader thread, armed POSIX CPU timers would be left on a list but freed, leading to a use-after-free.
Affected products
- Canonical Ubuntu Linux: version 20.04 only; version 22.04 only
- Linux Linux Kernel: from 5.7, before 5.10.137 (fixed in 5.10.137); from 5.11, before 5.15.61 (fixed in 5.15.61); from 5.16, before 5.18.18 (fixed in 5.18.18); from 5.19, before 5.19.2 (fixed in 5.19.2)
Published 2024-01-08. Last modified 2026-06-17.