Skip to content

kernel CVE-2022-25636

High
arnaldo2792 published GHSA-7hf7-4wvh-89m4 Apr 25, 2022

Package

kernel-5.10 (bottlerocket)

Affected versions

< 1.7.2

Patched versions

1.7.2
kernel-5.4 (bottlerocket)
< 1.7.2
1.7.2

Description

An out-of-bounds (OOB) memory access flaw was found in nft_fwd_dup_netdev_offload in net/netfilter/nf_dup_netdev.c in the netfilter subcomponent in the Linux kernel due to a heap out-of-bounds write problem. This flaw allows a local attacker with a user account on the system to gain access to out-of-bounds memory, leading to a system crash or a privilege escalation threat.

Severity

High

CVE ID

CVE-2022-25636

Weaknesses

No CWEs