CVE-2022-1882 is a use-after-free flaw in the Linux kernel's pipe notification and watch-queue functionality. A race between post_one_notification() and free_pipe_info() can leave watch_queue->pipe pointing to freed memory, allowing a local authenticated attacker to crash the host or potentially elevate privileges. The vulnerability was introduced by commit db8facfc9fafacefe8a835 and requires a difficult-to-win race condition; Red Hat rated it Moderate (CVSS 7.0), while NVD assigned CVSS 7.8.
Upstream Linux fixed the issue before kernel 5.18 final, with the remediation included in Fedora stable kernel 5.18.15. The patch serializes access to watch queues and their destruction state through new locking helpers, preventing notification paths from accessing invalid pipes or defunct queues. Red Hat remediated affected Red Hat Enterprise Linux 9 kernel and kernel-rt packages through RHSA-2023:2148 and RHSA-2023:2458; listed RHEL 6, 7, and 8 kernel variants were not affected.

Get the actors, campaigns, and ATT&CK mapping behind it.
4 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2023:2148 and RHSA-2023:2458 to fix CVE-2022-1882 in Red Hat Enterprise Linux 9 kernel and kernel-rt packages, and closed its tracking bug.
The Linux kernel pipe use-after-free vulnerability CVE-2022-1882 was reported. The flaw leaves a watch_queue pipe reference dangling after free_pipe_info() frees the pipe, enabling later access by post_one_notification().
Fedora incorporated the fix for CVE-2022-1882 into its stable Linux kernel 5.18.15 updates.
Linux upstream fixed CVE-2022-1882 in kernel version 5.18-rc8 with changes that serialize access to watch queues and their defunct state, ensuring notification pipes remain valid while accessed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
bugzilla.redhat.com
Open sourceredhat.com
Open sourcegit.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.