CVE-2022-2602 is a Linux kernel use-after-free vulnerability affecting io_uring and involving Unix SCM garbage collection. The provided content explicitly characterizes it as an "io_uring UAF, Unix SCM garbage collection" issue and states that it is a use-after-free leading to local privilege escalation. The fix commit reportedly did not mention the security implications, making it an example of a silent security fix. Based on the available information, the vulnerable condition arises from a lifetime-management flaw in kernel memory handling associated with io_uring and Unix SCM garbage collection, allowing freed kernel objects to be referenced after release.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains two local privilege escalation exploits targeting CVE-2022-2602 in the Linux kernel. The exploits are implemented in C and use advanced techniques (userfaultfd and inode locking) to exploit a race condition in io_uring file registration. Both exploits attempt to overwrite /etc/passwd by leveraging a race condition, injecting a new root user ('pwned' with password 'lol') into the system. The Makefile is provided for compilation, requiring liburing-dev. The exploits require local access and the ability to execute binaries. The main files are 'poc_inode_locking.c' and 'poc_userfaultfd.c', each demonstrating a different exploitation technique for the same vulnerability. The endpoints of interest are /tmp/rwA (used for the race) and /etc/passwd (the privilege escalation target).
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.