Skip to content

kernel CVE-2022-4378

High
rpkelly published GHSA-xjgr-cm78-34qq Mar 21, 2023

Package

kernel-5.10 (bottlerocket)

Affected versions

< 1.13.0

Patched versions

1.13.0
kernel-5.15 (bottlerocket)
< 1.13.0
1.13.0

Description

A stack overflow flaw was found in the Linux kernel's SYSCTL subsystem in how a user changes certain kernel parameters and variables. This flaw allows a local user to crash or potentially escalate their privileges on the system.

To trigger this issue, the user needs some privileges (for example, access to the sysctl files), but usually less than root or CAP_NET_ADMIN.

Severity

High

CVE ID

CVE-2022-4378

Weaknesses

No CWEs