Skip to content

kernel CVE-2022-1012

Moderate
rpkelly published GHSA-g9px-j6j3-h52v Aug 3, 2022

Package

kernel-5.10 (bottlerocket)

Affected versions

< 1.9.0

Patched versions

1.9.0
kernel-5.4 (bottlerocket)
< 1.9.0
1.9.0

Description

Due to the small table perturb size, a memory leak flaw was found in the Linux kernel’s TCP source port generation algorithm in the net/ipv4/tcp.c function. This flaw allows an attacker to leak information and may cause a denial of service.

Severity

Moderate

CVE ID

CVE-2022-1012

Weaknesses

No CWEs