CVE-2022-2639
Summary
| CVE | CVE-2022-2639 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-09-01 21:15:00 UTC |
| Updated | 2024-02-02 02:36:00 UTC |
| Description | An integer coercion error was found in the openvswitch kernel module. Given a sufficiently large number of actions, while copying and reserving memory for a new action of a new flow, the reserve_sfa_size() function does not return -EMSGSIZE as expected, potentially leading to an out-of-bounds write access. This flaw allows a local user to crash or potentially escalate their privileges on the system. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| openvswitch: fix OOB access in reserve_sfa_size() · torvalds/linux@cefa91b · GitHub |
MISC |
github.com |
|
| 2084479 – (CVE-2022-2639) CVE-2022-2639 kernel: openvswitch: integer underflow leads to out-of-bounds write in reserve_sfa_size() |
MISC |
bugzilla.redhat.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160210 Oracle Enterprise Linux Security Update for kernel (ELSA-2022-7683)
- 160270 Oracle Enterprise Linux Security Update for kernel (ELSA-2022-8267)
- 160345 Oracle Enterprise Linux Security Update for unbreakable enterprise kernel (ELSA-2022-10065)
- 180913 Debian Security Update for linux (CVE-2022-2639)
- 240815 Red Hat Update for kernel-rt (RHSA-2022:7444)
- 240817 Red Hat Update for kernel security (RHSA-2022:7683)
- 240869 Red Hat Update for kernel-rt (RHSA-2022:7933)
- 240904 Red Hat Update for kernel security (RHSA-2022:8267)
- 240957 Red Hat Update for kernel-rt (RHSA-2022:8765)
- 240958 Red Hat Update for kpatch-patch (RHSA-2022:8768)
- 240959 Red Hat Update for kernel (RHSA-2022:8767)
- 240968 Red Hat Update for kernel (RHSA-2022:8809)
- 240969 Red Hat Update for kpatch-patch (RHSA-2022:8831)
- 241003 Red Hat Update for kernel-rt (RHSA-2022:8941)
- 241008 Red Hat Update for kernel (RHSA-2022:8973)
- 241009 Red Hat Update for kernel-rt (RHSA-2022:8974)
- 241022 Red Hat Update for kpatch-patch (RHSA-2022:9082)
- 241619 Red Hat Update for kpatch-patch (RHSA-2023:0059)
- 241682 Red Hat Update for kernel (RHSA-2023:0058)
- 355565 Amazon Linux Security Advisory for kernel : ALAS2KERNEL-5.15-2023-023
- 377117 Alibaba Cloud Linux Security Update for cloud-kernel (ALINUX3-SA-2022:0158)
- 377597 Alibaba Cloud Linux Security Update for cloud-kernel (ALINUX2-SA-2022:0040)
- 377871 Alibaba Cloud Linux Security Update for cloud-kernel (ALINUX2-SA-2023:0001)
- 390269 Oracle VM Server for x86 Security Update for kernel (OVMSA-2022-0031)
- 672205 EulerOS Security Update for kernel (EulerOS-SA-2022-2466)
- 672278 EulerOS Security Update for kernel (EulerOS-SA-2022-2686)
- 672286 EulerOS Security Update for kernel (EulerOS-SA-2022-2654)
- 672354 EulerOS Security Update for kernel (EulerOS-SA-2022-2732)
- 672391 EulerOS Security Update for kernel (EulerOS-SA-2022-2767)
- 752502 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:2875-1)
- 752584 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:3265-1)
- 752591 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:3274-1)
- 752592 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:3282-1)
- 752594 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:3293-1)
- 752596 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:3291-1)
- 752615 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:3408-1)
- 752632 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:3450-1)
- 753063 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:4617-1)
- 753167 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:3288-1)
- 753316 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:2892-1)
- 753370 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:3609-1)
- 940732 AlmaLinux Security Update for kernel (ALSA-2022:7683)
- 940766 AlmaLinux Security Update for kernel-rt (ALSA-2022:7444)
- 940798 AlmaLinux Security Update for kernel (ALSA-2022:8267)
- 940843 AlmaLinux Security Update for kernel-rt (ALSA-2022:7933)
- 960176 Rocky Linux Security Update for kernel-rt (RLSA-2022:7444)
- 960184 Rocky Linux Security Update for kernel (RLSA-2022:7683)