CVE-2022-4378
Vulnerability Summary
Timeline
Description
A stack overflow flaw was found in the Linux kernel's SYSCTL subsystem in how a user changes certain kernel parameters and variables. This flaw allows a local user to crash or potentially escalate their privileges on the system.
CVSS Metrics
- v3.1•HIGH•Score: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Trends
Current EPSS score: 0.43%• Percentile: 37%
Techniques & Countermeasures
- CWE-131•Incorrect Calculation of Buffer Size
The product does not correctly calculate the size to be used when allocating a buffer, which could lead to a buffer overflow.
- CWE-787•Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
Affected Systems
- debian•linux
< 5.10.158-1 | < 6.0.12-1 | < 6.0.12-1 | < 6.0.12-1
- linux•linux_kernel
≥ 4.9.0, ≤ 4.9.337 | ≥ 4.14.0, ≤ 4.14.302 | ≥ 4.19.0, ≤ 4.19.269 | ≥ 5.4.0, ≤ 5.4.228 | ≥ 5.10.0, ≤ 5.10.162 | ≥ 5.15.0, ≤ 5.15.86 | ≥ 6.0.0, ≤ 6.0.11
- redhat•bpftool
< 0:3.10.0-1062.71.1.el7 | < 0:4.18.0-193.100.1.el8_2 | < 0:3.10.0-957.100.1.el7
- redhat•bpftool-debuginfo
< 0:3.10.0-1062.71.1.el7 | < 0:4.18.0-193.100.1.el8_2
- redhat•kernel
< 0:3.10.0-1062.71.1.el7 | < 0:4.18.0-193.100.1.el8_2 | < 0:3.10.0-957.100.1.el7 | < 0:3.10.0-693.107.1.el7 | < 0:2.6.32-754.50.1.el6
- redhat•kernel-abi-whitelists
< 0:3.10.0-1062.71.1.el7 | < 0:4.18.0-193.100.1.el8_2 | < 0:3.10.0-957.100.1.el7 | < 0:3.10.0-693.107.1.el7 | < 0:2.6.32-754.50.1.el6
- redhat•kernel-bootwrapper
< 0:3.10.0-1062.71.1.el7
- redhat•kernel-core
< 0:4.18.0-193.100.1.el8_2
- redhat•kernel-debug
< 0:3.10.0-1062.71.1.el7 | < 0:4.18.0-193.100.1.el8_2 | < 0:3.10.0-957.100.1.el7 | < 0:3.10.0-693.107.1.el7 | < 0:2.6.32-754.50.1.el6
- redhat•kernel-debug-core
< 0:4.18.0-193.100.1.el8_2
- redhat•kernel-debug-debuginfo
< 0:3.10.0-1062.71.1.el7 | < 0:4.18.0-193.100.1.el8_2 | < 0:3.10.0-957.100.1.el7 | < 0:3.10.0-693.107.1.el7 | < 0:2.6.32-754.50.1.el6
- redhat•kernel-debug-devel
< 0:3.10.0-1062.71.1.el7 | < 0:4.18.0-193.100.1.el8_2 | < 0:3.10.0-957.100.1.el7 | < 0:3.10.0-693.107.1.el7 | < 0:2.6.32-754.50.1.el6
- redhat•kernel-debug-modules
< 0:4.18.0-193.100.1.el8_2
- redhat•kernel-debug-modules-extra
< 0:4.18.0-193.100.1.el8_2
- redhat•kernel-debuginfo
< 0:3.10.0-1062.71.1.el7 | < 0:4.18.0-193.100.1.el8_2 | < 0:3.10.0-957.100.1.el7 | < 0:3.10.0-693.107.1.el7 | < 0:2.6.32-754.50.1.el6
- redhat•kernel-debuginfo-common-i686
< 0:2.6.32-754.50.1.el6
- redhat•kernel-debuginfo-common-ppc64le
< 0:3.10.0-1062.71.1.el7 | < 0:4.18.0-193.100.1.el8_2
- redhat•kernel-debuginfo-common-s390x
< 0:2.6.32-754.50.1.el6
- redhat•kernel-debuginfo-common-x86_64
< 0:3.10.0-1062.71.1.el7 | < 0:4.18.0-193.100.1.el8_2 | < 0:3.10.0-957.100.1.el7 | < 0:3.10.0-693.107.1.el7 | < 0:2.6.32-754.50.1.el6
- redhat•kernel-devel
< 0:3.10.0-1062.71.1.el7 | < 0:4.18.0-193.100.1.el8_2 | < 0:3.10.0-957.100.1.el7 | < 0:3.10.0-693.107.1.el7 | < 0:2.6.32-754.50.1.el6
- redhat•kernel-doc
< 0:3.10.0-1062.71.1.el7 | < 0:4.18.0-193.100.1.el8_2 | < 0:3.10.0-957.100.1.el7 | < 0:3.10.0-693.107.1.el7 | < 0:2.6.32-754.50.1.el6
- redhat•kernel-firmware
< 0:2.6.32-754.50.1.el6
- redhat•kernel-kdump
< 0:2.6.32-754.50.1.el6
- redhat•kernel-kdump-debuginfo
< 0:2.6.32-754.50.1.el6
- redhat•kernel-kdump-devel
< 0:2.6.32-754.50.1.el6
- redhat•kernel-modules
< 0:4.18.0-193.100.1.el8_2
- redhat•kernel-modules-extra
< 0:4.18.0-193.100.1.el8_2
- redhat•kernel-rt
< 0:4.18.0-193.100.1.rt13.151.el8_2 | < 0:4.18.0-193.100.1.rt13.151.el8_2
- redhat•kernel-rt-core
< 0:4.18.0-193.100.1.rt13.151.el8_2 | < 0:4.18.0-193.100.1.rt13.151.el8_2
- redhat•kernel-rt-debug
< 0:4.18.0-193.100.1.rt13.151.el8_2 | < 0:4.18.0-193.100.1.rt13.151.el8_2
- redhat•kernel-rt-debug-core
< 0:4.18.0-193.100.1.rt13.151.el8_2 | < 0:4.18.0-193.100.1.rt13.151.el8_2
- redhat•kernel-rt-debug-debuginfo
< 0:4.18.0-193.100.1.rt13.151.el8_2 | < 0:4.18.0-193.100.1.rt13.151.el8_2
- redhat•kernel-rt-debug-devel
< 0:4.18.0-193.100.1.rt13.151.el8_2 | < 0:4.18.0-193.100.1.rt13.151.el8_2
- redhat•kernel-rt-debug-kvm
< 0:4.18.0-193.100.1.rt13.151.el8_2
- redhat•kernel-rt-debug-modules
< 0:4.18.0-193.100.1.rt13.151.el8_2 | < 0:4.18.0-193.100.1.rt13.151.el8_2
- redhat•kernel-rt-debug-modules-extra
< 0:4.18.0-193.100.1.rt13.151.el8_2 | < 0:4.18.0-193.100.1.rt13.151.el8_2
- redhat•kernel-rt-debuginfo
< 0:4.18.0-193.100.1.rt13.151.el8_2 | < 0:4.18.0-193.100.1.rt13.151.el8_2
- redhat•kernel-rt-debuginfo-common-x86_64
< 0:4.18.0-193.100.1.rt13.151.el8_2 | < 0:4.18.0-193.100.1.rt13.151.el8_2
- redhat•kernel-rt-devel
< 0:4.18.0-193.100.1.rt13.151.el8_2 | < 0:4.18.0-193.100.1.rt13.151.el8_2
- redhat•kernel-rt-kvm
< 0:4.18.0-193.100.1.rt13.151.el8_2
- redhat•kernel-rt-modules
< 0:4.18.0-193.100.1.rt13.151.el8_2 | < 0:4.18.0-193.100.1.rt13.151.el8_2
- redhat•kernel-rt-modules-extra
< 0:4.18.0-193.100.1.rt13.151.el8_2 | < 0:4.18.0-193.100.1.rt13.151.el8_2
- redhat•kernel-tools
< 0:3.10.0-1062.71.1.el7 | < 0:4.18.0-193.100.1.el8_2 | < 0:3.10.0-957.100.1.el7 | < 0:3.10.0-693.107.1.el7
- redhat•kernel-tools-debuginfo
< 0:3.10.0-1062.71.1.el7 | < 0:4.18.0-193.100.1.el8_2 | < 0:3.10.0-957.100.1.el7 | < 0:3.10.0-693.107.1.el7
- redhat•kernel-tools-libs
< 0:3.10.0-1062.71.1.el7 | < 0:4.18.0-193.100.1.el8_2 | < 0:3.10.0-957.100.1.el7 | < 0:3.10.0-693.107.1.el7
- redhat•kernel-tools-libs-devel
< 0:3.10.0-1062.71.1.el7 | < 0:3.10.0-957.100.1.el7 | < 0:3.10.0-693.107.1.el7
- redhat•kpatch-patch-3_10_0-1062_68_1
< 0:1-1.el7
- redhat•kpatch-patch-3_10_0-1062_68_1-debuginfo
< 0:1-1.el7
- redhat•kpatch-patch-3_10_0-1062_70_1
< 0:1-1.el7
- redhat•kpatch-patch-3_10_0-1062_70_1-debuginfo
< 0:1-1.el7
Showing first 50 affected entries in server-rendered view.
References (28)
- https://bugzilla.redhat.com/show_bug.cgi?id=2152548
- https://git.kernel.org/pub/scm/linux/kernel/git/stable/stable-queue.git/tree/queue-6.0/proc-avoid-integer-type-confusion-in-get_proc_long.patch
- https://git.kernel.org/pub/scm/linux/kernel/git/stable/stable-queue.git/tree/queue-6.0/proc-proc_skip_spaces-shouldn-t-think-it-is-working-on-c-strings.patch
- https://seclists.org/oss-sec/2022/q4/178
- http://packetstormsecurity.com/files/171289/Kernel-Live-Patch-Security-Notice-LNS-0092-1.html
- https://access.redhat.com/errata/RHSA-2023:0944
- https://access.redhat.com/security/updates/classification/#important
- https://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_0944.json
- https://access.redhat.com/security/cve/CVE-2022-4378
- https://www.cve.org/CVERecord?id=CVE-2022-4378
- https://nvd.nist.gov/vuln/detail/CVE-2022-4378
- https://access.redhat.com/errata/RHSA-2023:0945
- https://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_0945.json
- https://access.redhat.com/errata/RHSA-2023:1101
- https://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_1101.json
- https://access.redhat.com/errata/RHSA-2023:1103
- https://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_1103.json
- https://access.redhat.com/errata/RHSA-2023:1109
- https://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_1109.json
- https://access.redhat.com/errata/RHSA-2023:1110
- https://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_1110.json
- https://access.redhat.com/errata/RHSA-2023:1705
- https://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_1705.json
- https://access.redhat.com/errata/RHSA-2023:1706
- https://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_1706.json
- https://access.redhat.com/errata/RHSA-2023:1822
- https://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_1822.json
- https://security-tracker.debian.org/tracker/CVE-2022-4378