CVE-2022-0435
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD
Description
A stack overflow flaw was found in the Linux kernel's TIPC protocol functionality in the way a user sends a packet with malicious content where the number of domain member nodes is higher than the 64 allowed. This flaw allows a remote user to crash the system or possibly escalate their privileges if they have access to the TIPC network.
Affected (51)
Products: Linux: Linux Kernel · Redhat: Codeready Linux Builder, Codeready Linux Builder Eus, Codeready Linux Builder Eus For Power Little Endian, Codeready Linux Builder For Power Little Endian Eus, Enterprise Linux Eus, Enterprise Linux For Ibm Z Systems, Enterprise Linux For Ibm Z Systems Eus, Enterprise Linux For Power Little Endian, Enterprise Linux For Power Little Endian Eus, Enterprise Linux For Real Time, Enterprise Linux For Real Time For Nfv, Enterprise Linux For Real Time For Nfv Tus, Enterprise Linux For Real Time Tus, Enterprise Linux Server Aus, Enterprise Linux Server For Power Little Endian Update Services For Sap Solutions, Enterprise Linux Server Tus, Enterprise Linux Server Update Services For Sap Solutions, Virtualization, Virtualization Host · Ovirt: Node · +2 more
Show all products
Linux: Linux Kernel · Redhat: Codeready Linux Builder, Codeready Linux Builder Eus, Codeready Linux Builder Eus For Power Little Endian, Codeready Linux Builder For Power Little Endian Eus, Enterprise Linux Eus, Enterprise Linux For Ibm Z Systems, Enterprise Linux For Ibm Z Systems Eus, Enterprise Linux For Power Little Endian, Enterprise Linux For Power Little Endian Eus, Enterprise Linux For Real Time, Enterprise Linux For Real Time For Nfv, Enterprise Linux For Real Time For Nfv Tus, Enterprise Linux For Real Time Tus, Enterprise Linux Server Aus, Enterprise Linux Server For Power Little Endian Update Services For Sap Solutions, Enterprise Linux Server Tus, Enterprise Linux Server Update Services For Sap Solutions, Virtualization, Virtualization Host · Ovirt: Node · Fedoraproject: Fedora · Netapp: H300e Firmware, H300s Firmware, H410s Firmware, H500e Firmware, H500s Firmware, H700e Firmware, H700s Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 4.10 to 4.14.266 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 8.0 | |
| Version 8.2 | |
| Version 8.2 | |
| Version 8.0 | |
| Version 8.2 | |
| Version 8.0 | |
| Version 8.2 | |
| Version 8.0 | |
| Version 8.2 | |
| Version 8 | |
| Version 8 | |
| Version 8.2 | |
| Version 8.2 | |
| Version 8.2 | |
| Version 8.2 | |
| Version 8.2 | |
| Version 8.2 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.0 | |
| Version 4.0 |
| Running on/with | Platform Versions |
|---|---|
Redhat Enterprise Linux | Version 8.0 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 34 |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netapp H300e | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netapp H300s | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netapp H410s | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netapp H500e | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netapp H500s | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netapp H700e | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netapp H700s | All versions |
References (6)
Source: secalert@redhat.com
Issue TrackingPatchThird Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
ExploitMailing ListMitigationPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing ListMitigationPatchThird Party Advisory
Timeline
No history available yet.