{"id":"CVE-2022-1462","details":"An out-of-bounds read flaw was found in the Linux kernel’s TeleTYpe subsystem. The issue occurs in how a user triggers a race condition using ioctls TIOCSPTLCK and TIOCGPTPEER and TIOCSTI and TCXONC with leakage of memory in the flush_to_ldisc function. This flaw allows a local user to crash the system or read unauthorized random data from memory.","modified":"2026-03-14T11:24:21.056189Z","published":"2022-06-02T14:15:32.637Z","related":["ALSA-2023:2148","ALSA-2023:2458","ALSA-2023:2736","ALSA-2023:2951","CGA-mcwh-q4vm-9f29","SUSE-SU-2022:2520-1","SUSE-SU-2022:2719-1","SUSE-SU-2022:2720-1","SUSE-SU-2022:2721-1","SUSE-SU-2022:2722-1","SUSE-SU-2022:2723-1","SUSE-SU-2022:2741-1","SUSE-SU-2022:2808-1","SUSE-SU-2022:2809-1","SUSE-SU-2022:2827-1","SUSE-SU-2022:2840-1","SUSE-SU-2022:2875-1","SUSE-SU-2022:2875-2","SUSE-SU-2022:2892-1","SUSE-SU-2022:2892-2","SUSE-SU-2022:2910-1","SUSE-SU-2023:0416-1","openSUSE-SU-2024:12193-1","openSUSE-SU-2024:13704-1"],"references":[{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2022/10/msg00000.html"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2078466"},{"type":"EVIDENCE","url":"https://seclists.org/oss-sec/2022/q2/155"}],"affected":[{"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-1462.json","unresolved_ranges":[{"events":[{"introduced":"0"},{"last_affected":"8.0"}]},{"events":[{"introduced":"0"},{"last_affected":"9.0"}]},{"events":[{"introduced":"0"},{"last_affected":"10.0"}]}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H"}]}