CVE-2022-36946

Advisory lineage Upstream: 0 Downstream: 55
Modified
Published: 27 Jul 2022, 00:00
Last modified:05 May 2025, 16:13

Vulnerability Summary

Overall Risk (default)
medium
31/100
CVSS Score
7.5 HIGH
v3.1 (cve.org)
EPSS Score
5.08% LOW
5% probability +0.38%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

27 Jul 2022, 00:00
Published
Vulnerability first disclosed
05 May 2025, 16:13
Last Modified
Vulnerability information updated

Description

nfqnl_mangle in net/netfilter/nfnetlink_queue.c in the Linux kernel through 5.18.14 allows remote attackers to cause a denial of service (panic) because, in the case of an nf_queue verdict with a one-byte nfta_payload attribute, an skb_pull can encounter a negative skb->len.

CVSS Metrics

  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 5.08% Percentile: 90%

Affected Systems

  • debiandebian_linux

    10.0 | 11.0

  • linuxlinux_kernel

    ≥ 2.6.14, < 4.9.326 | ≥ 4.10, < 4.14.291 | ≥ 4.15, < 4.19.255 | ≥ 4.20, < 5.4.209 | ≥ 5.5, < 5.10.135 | ≥ 5.11, < 5.15.59 | ≥ 5.16, < 5.18.16

  • netappactive_iq_unified_manager

    na

  • netapphci_compute_node_firmware

    na

  • netappsolidfire_\&_hci_management_node

    na

  • netappsolidfire_\&_hci_storage_node

    na

  • netappsolidfire_enterprise_sds

    na

References (6)