5.5

CVE-2022-2905

Exploit
An out-of-bounds memory read flaw was found in the Linux kernel's BPF subsystem in how a user calls the bpf_tail_call function with a key larger than the max_entries of the map. This flaw allows a local user to gain unauthorized access to data.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version < 6.0
Linux ≫ Linux Kernel Version 6.0 Update rc1
Linux ≫ Linux Kernel Version 6.0 Update rc2
Linux ≫ Linux Kernel Version 6.0 Update rc3
Redhat ≫ Enterprise Linux Version 8.0
Debian ≫ Debian Linux Version 10.0
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.35% 0.279
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CWE-125 Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

https://lists.debian.org/debian-lts-announce/2022/11/msg00001.html
Third Party Advisory
Mailing List
https://bugzilla.redhat.com/show_bug.cgi?id=2121800
Patch
Third Party Advisory
Exploit
Issue Tracking
https://lore.kernel.org/bpf/984b37f9fdf7ac36831d2137415a4a915744c1b6.1661462653.git.daniel%40iogearbox.net/