Skip to content

kernel CVE-2022-33743

Moderate
rpkelly published GHSA-w8jq-c399-98rh Jul 29, 2022

Package

kernel-5.10 (bottlerocket)

Affected versions

< 1.9.0

Patched versions

1.9.0
kernel-5.15 (bottlerocket)
< 1.9.0
1.9.0

Description

Network backend may cause Linux netfront to use freed SKBs. While adding logic to support XDP (eXpress Data Path), a code label was moved in a way allowing for SKBs having references (pointers) retained for further processing to nevertheless be freed.

Severity

Moderate

CVE ID

CVE-2022-33743

Weaknesses

No CWEs