Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-27666

Опубликовано: 23 мар. 2022
Источник: debian

Описание

A heap buffer overflow flaw was found in IPsec ESP transformation code in net/ipv4/esp4.c and net/ipv6/esp6.c. This flaw allows a local attacker with a normal user privilege to overwrite kernel heap objects and may cause a local privilege escalation threat.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
linuxfixed5.16.18-1package
linuxnot-affectedstretchpackage

Примечания

  • https://git.kernel.org/linus/ebe48d368e97d007bfeb76fcb065d6cfc4c96645 (5.17-rc8)

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 3 лет назад

A heap buffer overflow flaw was found in IPsec ESP transformation code in net/ipv4/esp4.c and net/ipv6/esp6.c. This flaw allows a local attacker with a normal user privilege to overwrite kernel heap objects and may cause a local privilege escalation threat.

CVSS3: 7.8
redhat
больше 3 лет назад

A heap buffer overflow flaw was found in IPsec ESP transformation code in net/ipv4/esp4.c and net/ipv6/esp6.c. This flaw allows a local attacker with a normal user privilege to overwrite kernel heap objects and may cause a local privilege escalation threat.

CVSS3: 7.8
nvd
около 3 лет назад

A heap buffer overflow flaw was found in IPsec ESP transformation code in net/ipv4/esp4.c and net/ipv6/esp6.c. This flaw allows a local attacker with a normal user privilege to overwrite kernel heap objects and may cause a local privilege escalation threat.

CVSS3: 7.8
msrc
около 3 лет назад

Описание отсутствует

suse-cvrf
около 3 лет назад

Security update for the Linux Kernel (Live Patch 20 for SLE 12 SP4)