Red Hat remediated CVE-2022-42703, a moderate-severity Linux kernel memory-management flaw in mm/rmap.c involving incorrect double reuse of a leaf anon_vma in is_mergeable_anon_vma(). An unprivileged local attacker could repeatedly invoke fork and memory operations to trigger a use-after-free and memory leak, causing a system crash. The issue affects kernels before version 5.19.7; upstream fixed it in commit 2555283eb40df89945557273121e9393ef9b542b.
Red Hat rated the flaw CVSS 3.1 5.5, with high availability impact and no assessed confidentiality or integrity impact. Fixes were issued for RHEL 7, 8, 8.6 Extended Update Support, 9, 9.0 Extended Update Support, and Red Hat Virtualization 4 on RHEL 8; Fedora incorporated the stable 5.19.7 kernel fix. RHSA-2023:3388 delivered the fix for RHEL 8.6 EUS alongside patches for three other kernel vulnerabilities. Organizations should install the applicable updated kernel packages and reboot affected systems; Red Hat identified no separate supported mitigation.

See affected versions and whether adversaries are exploiting it.
9 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2023:1091 and RHSA-2023:1092 to fix CVE-2022-42703 in the RHEL 7 kernel and kernel-rt packages.
Red Hat released RHSA-2023:4137 and RHSA-2023:4138 to address CVE-2022-42703 in the RHEL 9.0 Extended Update Support kernel and kernel-rt packages.
Red Hat closed its Bugzilla tracking issue for CVE-2022-42703 after issuing fixes for the affected product streams.
Red Hat published RHSA-2023:3388, an Important security advisory delivering an updated kernel for RHEL 8.6 Extended Update Support and affected associated offerings, including Red Hat Virtualization Host 4. The advisory remediated CVE-2022-42703 along with several other kernel vulnerabilities; systems require a reboot after installation.
Red Hat released RHSA-2023:2736 and RHSA-2023:2951 to remediate CVE-2022-42703 in RHEL 8 kernel-rt and kernel packages.
Red Hat released RHSA-2023:2148 and RHSA-2023:2458 to address CVE-2022-42703 in RHEL 9 kernel-rt and kernel packages.
Fedora remediated CVE-2022-42703 through stable kernel updates based on version 5.19.7.
The upstream Linux kernel addressed the flaw with commit 2555283eb40df89945557273121e9393ef9b542b; the fix was included in the Linux 5.19.7 changelog. Kernel versions before 5.19.7 were affected.
CVE-2022-42703 was identified as a use-after-free flaw in the Linux kernel's mm/rmap.c code, where repeated fork and memory operations can cause incorrect reuse of a leaf anon_vma. A low-privileged local attacker could crash an affected system.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
5 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.