Skip to content

kernel CVE-2022-0435

High
cbgbt published GHSA-rf58-v3c6-rf7r Mar 9, 2022

Package

kernel (bottlerocket)

Affected versions

< 1.6.2

Patched versions

1.6.2

Description

A stack overflow flaw was found in the Linux kernel's TIPC protocol functionality in the way a user sends a packet with malicious content where the number of domain member nodes is higher than the 64 allowed. This flaw allows a remote user to crash the system or possibly escalate their privileges if they have access to the TIPC network.

Severity

High

CVE ID

CVE-2022-0435

Weaknesses

No CWEs