← Back

CVE-2022-2639

nvd nist
Published: Sep 1, 2022Modified: Jun 17, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

An integer coercion error was found in the openvswitch kernel module. Given a sufficiently large number of actions, while copying and reserving memory for a new action of a new flow, the reserve_sfa_size() function does not return -EMSGSIZE as expected, potentially leading to an out-of-bounds write access. This flaw allows a local user to crash or potentially escalate their privileges on the system.

Affected (11)

1 product
Linux Kernel
1 product
Enterprise Linux
Configuration A
9 vulnerable
Vulnerable SoftwareAffected Versions
Linux
From 3.18.139 to 3.19
From 4.14.112 to 4.14.277
From 4.19.35 to 4.19.240
From 4.4.179 to 4.5
From 4.9.169 to 4.9.312
From 5.0.8 to 5.4.191
From 5.11 to 5.15.36
From 5.16 to 5.17.5
From 5.5 to 5.10.113
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
Version 8.0
Version 9.0

References (4)

Source: secalert@redhat.com
Issue TrackingPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatch

Timeline

No history available yet.