CVE-2022-30594

Advisory lineage Upstream: 0 Downstream: 46
Modified
Published: 12 May 2022, 00:00
Last modified:03 Aug 2024, 06:56

Vulnerability Summary

Overall Risk (default)
medium
41/100
CVSS Score
7.8 HIGH
v3.1 (nvd)
EPSS Score
0.02% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

12 May 2022, 00:00
Published
Vulnerability first disclosed
03 Aug 2024, 06:56
Last Modified
Vulnerability information updated

Description

The Linux kernel before 5.17.2 mishandles seccomp permissions. The PTRACE_SEIZE code path allows attackers to bypass intended restrictions on setting the PT_SUSPEND_SECCOMP flag.

CVSS Metrics

  • v3.1HIGHScore: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • v2.0MEDIUMScore: 4.4AV:L/AC:M/Au:N/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 0.02% Percentile: 6%

Techniques & Countermeasures

  • CWE-862Missing Authorization

    The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Affected Systems

  • debiandebian_linux

    9.0 | 10.0

  • linuxlinux_kernel

    < 4.19.238 | ≥ 4.20, < 5.4.189 | ≥ 5.5.0, < 5.10.110 | ≥ 5.11, < 5.15.33 | ≥ 5.16.0, < 5.16.19 | ≥ 5.17, < 5.17.2

  • netapp8300_firmware

    na

  • netapp8700_firmware

    na

  • netappa400_firmware

    na

  • netapph300s_firmware

    na

  • netapph410c_firmware

    na

  • netapph410s_firmware

    na

  • netapph500s_firmware

    na

  • netapph700s_firmware

    na

  • netapphci_compute_node_firmware

    na

  • netappsolidfire_\&_hci_management_node

    na

  • netappsolidfire\,_enterprise_sds_\&_hci_storage_node

    na

References (9)