An issue was discovered in the Linux kernel through 5.19.8. drivers/firmware/efi/capsule-loader.c has a race condition with a resultant use-after-free.
https://www.debian.org/security/2022/dsa-5257
https://lists.debian.org/debian-lts-announce/2022/11/msg00001.html
https://lists.debian.org/debian-lts-announce/2022/10/msg00000.html
https://github.com/torvalds/linux/commit/9cb636b5f6a8cc6d1b50809ec8f8d33ae0c84c95
Source: Mitre, NVD
Published: 2022-09-09
Updated: 2023-08-08
Base Score: 3.8
Vector: CVSS2#AV:L/AC:H/Au:S/C:N/I:N/A:C
Severity: Low
Base Score: 4.7
Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Severity: Medium
EPSS: 0.00018