CVE-2022-0500
Summary
| CVE | CVE-2022-0500 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-03-25 19:15:00 UTC |
| Updated | 2023-06-26 18:01:00 UTC |
| Description | A flaw was found in unrestricted eBPF usage by the BPF_BTF_LOAD, leading to a possible out-of-bounds memory write in the Linux kernel’s BPF subsystem due to the way a user loads BTF. This flaw allows a local user to crash or escalate their privileges on the system. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| kernel/git/torvalds/linux.git - Linux kernel source tree |
MISC |
git.kernel.org |
|
| kernel/git/torvalds/linux.git - Linux kernel source tree |
MISC |
git.kernel.org |
|
| kernel/git/torvalds/linux.git - Linux kernel source tree |
MISC |
git.kernel.org |
|
| kernel/git/torvalds/linux.git - Linux kernel source tree |
MISC |
git.kernel.org |
|
| CVE-2022-0500 Linux Kernel Vulnerability in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| kernel/git/torvalds/linux.git - Linux kernel source tree |
MISC |
git.kernel.org |
|
| kernel/git/torvalds/linux.git - Linux kernel source tree |
MISC |
git.kernel.org |
|
| kernel/git/torvalds/linux.git - Linux kernel source tree |
MISC |
git.kernel.org |
|
| 2044578 – (CVE-2022-0500) CVE-2022-0500 kernel: Linux ebpf logic vulnerability leads to critical memory read and write gaining root privileges |
MISC |
bugzilla.redhat.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 184526 Debian Security Update for linux (CVE-2022-0500)
- 198861 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-5518-1)
- 198897 Ubuntu Security Notification for Linux kernel (Intel IoTG) Vulnerabilities (USN-5564-1)
- 242890 Red Hat Update for kernel (RHSA-2024:0724)
- 282441 Fedora Security Update for kernel (FEDORA-2022-952bb7b856)
- 282445 Fedora Security Update for kernel (FEDORA-2022-edbd74424e)
- 353964 Amazon Linux Security Advisory for kernel : ALAS2KERNEL-5.15-2022-001
- 354327 Amazon Linux Security Advisory for kernel : ALAS2022-2022-083
- 354468 Amazon Linux Security Advisory for kernel : ALAS2022-2022-185
- 354542 Amazon Linux Security Advisory for kernel : ALAS-2022-185
- 355199 Amazon Linux Security Advisory for kernel : ALAS2023-2023-070
- 355565 Amazon Linux Security Advisory for kernel : ALAS2KERNEL-5.15-2023-023
- 377117 Alibaba Cloud Linux Security Update for cloud-kernel (ALINUX3-SA-2022:0158)
- 610451 Google Pixel Android December 2022 Security Patch Missing
- 900796 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (9271)
- 900902 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (9241)
- 901332 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (9271-1)
- 902055 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (9241-1)
- 906223 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (9271-2)
- 906393 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (9241-2)