CVE-2022-28388: Double Free
Last updated 25 April 2025
Other sources
Linux Kernel could allow a local attacker to execute arbitrary code on the system, caused by a double-free flaw in usb8devstartxmit in drivers/net/can/usb/usb8dev.c. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary code on the system.
— IBM
usb8devstartxmit in drivers/net/can/usb/usb8dev.c in the Linux kernel through 5.17.1 has a double free.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-28388?
CVE-2022-28388 is classified as a high severity vulnerability due to its potential to allow local attackers to execute arbitrary code.
How do I fix CVE-2022-28388?
To address CVE-2022-28388, you should update your Linux Kernel to a version that includes the security fix, such as 5.10.223-1 or later.
Which Linux Kernel versions are affected by CVE-2022-28388?
CVE-2022-28388 affects Linux Kernel versions up to and including 5.17.1.
What systems are impacted by CVE-2022-28388?
CVE-2022-28388 impacts various systems, including certain versions of IBM Security Verify Governance and multiple Debian and Fedora releases.
Can CVE-2022-28388 be exploited remotely?
CVE-2022-28388 requires local access to the system to exploit, thus it cannot be exploited remotely.