Skip to content

kernel CVE-2022-1015

High
arnaldo2792 published GHSA-f9r3-8pqj-g2h5 Apr 25, 2022

Package

kernel-5.10 (bottlerocket)

Affected versions

< 1.7.2

Patched versions

1.7.2
kernel-5.4 (bottlerocket)
< 1.7.2
1.7.2

Description

An out of bounds access was discovered in nf_tables expression evaluation due to validation of user register indices. It leads to local privilege escalation, for example by overwriting a stack return address OOB with a crafted nft_expr_payload.

Severity

High

CVE ID

CVE-2022-1015

Weaknesses

No CWEs