Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2022-3534

Опубликовано: 17 окт. 2022
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4.9
CVSS3: 5.5

Описание

A vulnerability classified as critical has been found in Linux Kernel. Affected is the function btf_dump_name_dups of the file tools/lib/bpf/btf_dump.c of the component libbpf. The manipulation leads to use after free. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211032.

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

DNE

esm-apps-legacy/xenial

needs-triage

esm-apps/bionic

released

1.21-0ubuntu1~18.04.1+esm1
esm-apps/focal

released

1.21-0ubuntu1~20.04.1
esm-apps/xenial

ignored

end of ESM support, was needs-triage
focal

released

1.21-0ubuntu1~20.04.1
jammy

DNE

kinetic

DNE

lunar

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

released

1.0.1-2ubuntu1
esm-apps/focal

released

0.5.0-1~ubuntu20.04.1+esm1
focal

ignored

end of standard support, was needed
jammy

released

0.5.0-1ubuntu22.04.1
kinetic

released

0.8.0-1ubuntu22.10.1
lunar

released

1.0.1-2ubuntu1
mantic

released

1.0.1-2ubuntu1
noble

released

1.0.1-2ubuntu1
oracular

released

1.0.1-2ubuntu1

Показывать по

EPSS

Процентиль: 58%
0.00905
Низкий

4.9 Medium

CVSS2

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
redhat
почти 4 года назад

A vulnerability classified as critical has been found in Linux Kernel. Affected is the function btf_dump_name_dups of the file tools/lib/bpf/btf_dump.c of the component libbpf. The manipulation leads to use after free. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211032.

CVSS3: 5.5
nvd
почти 4 года назад

A vulnerability has been found in Linux Kernel up to 5.10.162/5.15.85/6.0.15/6.1.1. The impacted element is the function btf_dump_name_dups of the file tools/lib/bpf/btf_dump.c of the component libbpf. The manipulation leads to use after free. Upgrading to version 5.10.163, 5.15.86, 6.0.16, 6.1.2 and 6.2 is sufficient to resolve this issue. The identifier of the patch is c61650b869e0b6fb0c0a28ed42d928eea969afc8/fbe08093fb2334549859829ef81d42570812597d/8c64a8e76eb85d422af5ec60ccbf26e3ead8c333/a733bf10198eb5bb927890940de8ab457491ed3b/93c660ca40b5d2f7c1b1626e955a8e9fa30e0749. You should upgrade the affected component.

CVSS3: 5.5
debian
почти 4 года назад

A vulnerability has been found in Linux Kernel up to 5.10.162/5.15.85/ ...

CVSS3: 8
github
почти 4 года назад

A vulnerability classified as critical has been found in Linux Kernel. Affected is the function btf_dump_name_dups of the file tools/lib/bpf/btf_dump.c of the component libbpf. The manipulation leads to use after free. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211032.

CVSS3: 8
fstec
почти 4 года назад

Уязвимость функции btf_dump_name_dups() в модуле tools/lib/bpf/btf_dump.c библиотеки libbpf (Berkeley Packet Filters) ядра операционной системы Linux, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 58%
0.00905
Низкий

4.9 Medium

CVSS2

5.5 Medium

CVSS3