Описание
A heap buffer overflow flaw was found in IPsec ESP transformation code in net/ipv4/esp4.c and net/ipv6/esp6.c. This flaw allows a local attacker with a normal user privilege to overwrite kernel heap objects and may cause a local privilege escalation threat.
Меры по смягчению последствий
The given exploit needs CAP_NET_ADMIN to set up IPsec SA and a user namespace is used to get that capability, so disabling unprivileged user namespaces gives some protection.
Note: If the target system is already using IPsec and has SA configured, then no additional privileges are needed to exploit the issue.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 6 | kernel | Not affected | ||
Red Hat Enterprise Linux 7 | kernel | Not affected | ||
Red Hat Enterprise Linux 7 | kernel-rt | Not affected | ||
Red Hat Enterprise Linux 8 | kernel-rt | Fixed | RHSA-2022:5344 | 28.06.2022 |
Red Hat Enterprise Linux 8 | kpatch-patch | Fixed | RHSA-2022:5219 | 28.06.2022 |
Red Hat Enterprise Linux 8 | kernel | Fixed | RHSA-2022:5316 | 30.06.2022 |
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions | kernel | Fixed | RHSA-2022:4924 | 07.06.2022 |
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions | kpatch-patch | Fixed | RHSA-2022:4942 | 08.06.2022 |
Red Hat Enterprise Linux 8.2 Extended Update Support | kernel-rt | Fixed | RHSA-2022:5224 | 28.06.2022 |
Red Hat Enterprise Linux 8.2 Extended Update Support | kernel | Fixed | RHSA-2022:5220 | 28.06.2022 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.8 High
CVSS3
Связанные уязвимости
A heap buffer overflow flaw was found in IPsec ESP transformation code in net/ipv4/esp4.c and net/ipv6/esp6.c. This flaw allows a local attacker with a normal user privilege to overwrite kernel heap objects and may cause a local privilege escalation threat.
A heap buffer overflow flaw was found in IPsec ESP transformation code in net/ipv4/esp4.c and net/ipv6/esp6.c. This flaw allows a local attacker with a normal user privilege to overwrite kernel heap objects and may cause a local privilege escalation threat.
A heap buffer overflow flaw was found in IPsec ESP transformation code ...
Security update for the Linux Kernel (Live Patch 20 for SLE 12 SP4)
EPSS
7.8 High
CVSS3