kernel CVE-2022-4129
Package
kernel-5.10
(bottlerocket)
Affected versions
< 1.13.3
Patched versions
1.13.3
kernel-5.15
(bottlerocket)
< 1.13.3
1.13.3
A flaw was found in the Linux kernel's Layer 2 Tunneling Protocol (L2TP). A missing lock when clearing sk_user_data can lead to a race condition and NULL pointer dereference. This flaw could potentially lead to a system crash causing a denial of service.