kernel CVE-2022-2905
Package
kernel-5.10
(bottlerocket)
Affected versions
< 1.12.0
Patched versions
1.12.0
kernel-5.15
(bottlerocket)
< 1.12.0
1.12.0
An out-of-bounds memory read flaw was found in the Linux kernel's BPF subsystem in how a user calls the bpf_tail_call function with a key larger than the max_entries of the map. This flaw allows a local user to gain unauthorized access to data.