kernel CVE-2022-4378
Package
kernel-5.10
(bottlerocket)
Affected versions
< 1.13.0
Patched versions
1.13.0
kernel-5.15
(bottlerocket)
< 1.13.0
1.13.0
A stack overflow flaw was found in the Linux kernel's SYSCTL subsystem in how a user changes certain kernel parameters and variables. This flaw allows a local user to crash or potentially escalate their privileges on the system.
To trigger this issue, the user needs some privileges (for example, access to the sysctl files), but usually less than root or CAP_NET_ADMIN.