CVE-2022-50235
Vulnerability Summary
Timeline
Description
In the Linux kernel, the following vulnerability has been resolved: NFSD: Protect against send buffer overflow in NFSv2 READDIR Restore the previous limit on the @count argument to prevent a buffer overflow attack.
CVSS Metrics
- v3.1•HIGH•Score: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Trends
Current EPSS score: 0.02%• Percentile: 6%
Techniques & Countermeasures
- CWE-787•Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
Affected Systems
- linux•linux
≥ 9e291a6a28d32545ed2fd959a8165144d1724df1, < 0e57d696f60dee6117a8ace0cac7c5761d375277 | ≥ eabc0aab98e5218ceecd82069b0d6fdfff5ee885, < dc7f225090c29a5f3b9419b1af32846a201555e7 | ≥ 53b1119a6e5028b125f431a0116ba73510d82a72, < c2a878095b5c6f04f90553a3c45872f990dab14e | ≥ 53b1119a6e5028b125f431a0116ba73510d82a72, < f59c74df82f6ac9d2ea4e01aa3ae7c6c4481652d | ≥ 53b1119a6e5028b125f431a0116ba73510d82a72, < 00b4492686e0497fdb924a9d4c8f6f99377e176c | ≥ 5.15.12, < 5.15.75 | 5.16
- linux•linux_kernel
≥ 5.15.12, < 5.15.75 | ≥ 5.16.1, < 5.19.17 | ≥ 6.0, < 6.0.3 | 5.16 | 5.16:rc7 | 5.16:rc8
References (5)
- https://git.kernel.org/stable/c/0e57d696f60dee6117a8ace0cac7c5761d375277
- https://git.kernel.org/stable/c/dc7f225090c29a5f3b9419b1af32846a201555e7
- https://git.kernel.org/stable/c/c2a878095b5c6f04f90553a3c45872f990dab14e
- https://git.kernel.org/stable/c/f59c74df82f6ac9d2ea4e01aa3ae7c6c4481652d
- https://git.kernel.org/stable/c/00b4492686e0497fdb924a9d4c8f6f99377e176c