CVE-2022-23222
Summary
| CVE | CVE-2022-23222 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-01-14 08:15:00 UTC |
| Updated | 2023-11-07 03:44:00 UTC |
| Description | kernel/bpf/verifier.c in the Linux kernel through 5.15.14 allows local users to gain privileges because of the availability of pointer arithmetic via certain *_OR_NULL pointer types. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| oss-security - Re: Linux Kernel eBPF Improper Input Validation Vulnerability |
MLIST |
www.openwall.com |
|
| CVE-2022-23222 Linux Kernel Vulnerability in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
Third Party Advisory |
| oss-security - Re: Linux Kernel eBPF Improper Input Validation Vulnerability |
MLIST |
www.openwall.com |
|
| [SECURITY] Fedora 34 Update: kernel-5.16.11-100.fc34 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 35 Update: kernel-5.16.11-200.fc35 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
Mailing List, Third Party Advisory |
| oss-security - Re: Linux Kernel eBPF Improper Input Validation Vulnerability |
MLIST |
www.openwall.com |
|
| oss-security - Linux Kernel eBPF Improper Input Validation Vulnerability |
MISC |
www.openwall.com |
|
| [SECURITY] Fedora 35 Update: kernel-5.16.11-200.fc35 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| Debian -- Security Information -- DSA-5050-1 linux |
DEBIAN |
www.debian.org |
|
| [SECURITY] Fedora 34 Update: kernel-5.16.11-100.fc34 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
Mailing List, Third Party Advisory |
| oss-security - Re: Linux Kernel eBPF Improper Input Validation Vulnerability |
MLIST |
www.openwall.com |
|
| oss-security - Re: Linux Kernel eBPF Improper Input Validation Vulnerability |
MLIST |
www.openwall.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 179012 Debian Security Update for linux (DSA 5050-1)
- 182794 Debian Security Update for linux (CVE-2022-23222)
- 198659 Ubuntu Security Notification for Linux kernel (OEM) Vulnerabilities (USN-5278-1)
- 198708 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-5337-1)
- 198728 Ubuntu Security Notification for Linux kernel (Intel IOTG) Vulnerabilities (USN-5362-1)
- 198731 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-5368-1)
- 242890 Red Hat Update for kernel (RHSA-2024:0724)
- 282441 Fedora Security Update for kernel (FEDORA-2022-952bb7b856)
- 282445 Fedora Security Update for kernel (FEDORA-2022-edbd74424e)
- 353964 Amazon Linux Security Advisory for kernel : ALAS2KERNEL-5.15-2022-001
- 354327 Amazon Linux Security Advisory for kernel : ALAS2022-2022-083
- 354468 Amazon Linux Security Advisory for kernel : ALAS2022-2022-185
- 354542 Amazon Linux Security Advisory for kernel : ALAS-2022-185
- 355199 Amazon Linux Security Advisory for kernel : ALAS2023-2023-070
- 355565 Amazon Linux Security Advisory for kernel : ALAS2KERNEL-5.15-2023-023
- 377124 Alibaba Cloud Linux Security Update for cloud-kernel (ALINUX3-SA-2022:0029)
- 610418 Google Pixel Android June 2022 Security Patch Missing
- 752370 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:2520-1)
- 753148 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:2615-1)
- 900524 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (7492)
- 901874 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (7534-1)
- 905754 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (7492-1)