CVE-2022-20141 is a use-after-free flaw in the Linux kernel IPv4 IGMP implementation, in ip_check_mc_rcu within net/ipv4/igmp.c. Improper locking allows a local low-privileged user to race repeated opening and closing of IGMP inet sockets, potentially causing a kernel crash or escalating privileges; Android tracked the issue as A-112551163.
Red Hat rated the vulnerability Moderate with a CVSS v3.1 score of 7.0, noting that reliable exploitation has high complexity and that no reproducer was known. Fixes were released for Red Hat Enterprise Linux 8 and 9, including real-time kernel packages, and Fedora incorporated fixes in stable kernel 5.13.16 updates; RHEL 6 was not affected and RHEL 7 was outside support scope.

Get the actors, campaigns, and ATT&CK mapping behind it.
7 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2023:2736 for the RHEL 8 real-time kernel and RHSA-2023:2951 for the RHEL 8 kernel to fix CVE-2022-20141. Red Hat also closed Bug 2114937, its tracking issue for the vulnerability.
Red Hat released RHSA-2023:2148 for the RHEL 9 real-time kernel and RHSA-2023:2458 for the RHEL 9 kernel, addressing CVE-2022-20141.
Red Hat was notified of the Linux kernel IGMP use-after-free vulnerability affecting ip_check_mc_rcu.
CVE-2022-20141 was published for an Android kernel use-after-free in igmp.c's ip_check_mc_rcu function. The improper-locking flaw can be triggered locally by opening and closing inet sockets and may enable privilege escalation.
Fedora addressed CVE-2022-20141 in stable Linux kernel 5.13.16 updates.
RHSA-2024:0412 delivered a CVE-2022-20141 fix for the RHEL 8.6 Extended Update Support kernel and the Red Hat Virtualization 4 for RHEL 8 kernel package.
David S. Miller committed Linux kernel patch 23d2b94043ca8835bd1e67749020e839f396a1c2, authored by Liu Jian, to lock the multicast source list during ip_check_mc_rcu traversal. The change prevents concurrent ip_mc_del_src deletion from causing a use-after-free in IPv4 IGMP source filtering.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
5 references tracked. Mallory keeps watching after this page renders.
cve.org
Open sourceredhat.com
Open sourcebugzilla.redhat.com
Open sourcegit.kernel.org
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.