Linux Kernel libbpf btf_dump.c btf_dump_name_dups use after free
Summary
| CVE | CVE-2022-3534 |
|---|---|
| State | PUBLISHED |
| Assigner | VulDB |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-10-17 09:15:12 UTC |
| Updated | 2026-07-28 18:17:18 UTC |
| Description | A vulnerability has been found in Linux Kernel up to 5.10.162/5.15.85/6.0.15/6.1.1. The impacted element is the function btf_dump_name_dups of the file tools/lib/bpf/btf_dump.c of the component libbpf. The manipulation leads to use after free. Upgrading to version 5.10.163, 5.15.86, 6.0.16, 6.1.2 and 6.2 is sufficient to resolve this issue. The identifier of the patch is c61650b869e0b6fb0c0a28ed42d928eea969afc8/fbe08093fb2334549859829ef81d42570812597d/8c64a8e76eb85d422af5ec60ccbf26e3ead8c333/a733bf10198eb5bb927890940de8ab457491ed3b/93c660ca40b5d2f7c1b1626e955a8e9fa30e0749. You should upgrade the affected component. |
Risk And Classification
Primary CVSS: v4.0 5.1 MEDIUM from [email protected]
CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS: 0.005620000 probability, percentile 0.434260000 (date 2026-07-29)
Problem Types: CWE-119 | CWE-416 | CWE-416 Use After Free | CWE-119 Memory Corruption
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | [email protected] | Secondary | 5.1 | MEDIUM | CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/C... |
| 4.0 | CNA | DECLARED | 5.1 | MEDIUM | CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X |
| 3.1 | [email protected] | Primary | 8 | HIGH | CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | [email protected] | Secondary | 5.5 | MEDIUM | CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
| 3.1 | CNA | DECLARED | 5.5 | MEDIUM | CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C |
| 3.0 | CNA | DECLARED | 5.5 | MEDIUM | CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C |
| 2.0 | [email protected] | Secondary | 4.9 | AV:A/AC:M/Au:S/C:P/I:P/A:P | |
| 2.0 | CNA | DECLARED | 4.9 | AV:A/AC:M/Au:S/C:P/I:P/A:P/E:ND/RL:OF/RC:C |
CVSS v4.0 Breakdown
Attack Vector
AdjacentAttack Complexity
LowAttack Requirements
NonePrivileges Required
LowUser Interaction
NoneConfidentiality
LowIntegrity
LowAvailability
LowSub Conf.
NoneSub Integrity
NoneSub Availability
NoneCVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS v3.1 Breakdown
Attack Vector
AdjacentAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v3.0 Breakdown
Attack Vector
AdjacentAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
LowIntegrity
LowAvailability
LowCVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Linux | Linux Kernel | - | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Kernel | affected 5.10.162 | Not specified |
| CNA | Linux | Kernel | affected 5.15.0 | Not specified |
| CNA | Linux | Kernel | affected 5.15.1 | Not specified |
| CNA | Linux | Kernel | affected 5.15.2 | Not specified |
| CNA | Linux | Kernel | affected 5.15.3 | Not specified |
| CNA | Linux | Kernel | affected 5.15.4 | Not specified |
| CNA | Linux | Kernel | affected 5.15.5 | Not specified |
| CNA | Linux | Kernel | affected 5.15.6 | Not specified |
| CNA | Linux | Kernel | affected 5.15.7 | Not specified |
| CNA | Linux | Kernel | affected 5.15.8 | Not specified |
| CNA | Linux | Kernel | affected 5.15.9 | Not specified |
| CNA | Linux | Kernel | affected 5.15.10 | Not specified |
| CNA | Linux | Kernel | affected 5.15.11 | Not specified |
| CNA | Linux | Kernel | affected 5.15.12 | Not specified |
| CNA | Linux | Kernel | affected 5.15.13 | Not specified |
| CNA | Linux | Kernel | affected 5.15.14 | Not specified |
| CNA | Linux | Kernel | affected 5.15.15 | Not specified |
| CNA | Linux | Kernel | affected 5.15.16 | Not specified |
| CNA | Linux | Kernel | affected 5.15.17 | Not specified |
| CNA | Linux | Kernel | affected 5.15.18 | Not specified |
| CNA | Linux | Kernel | affected 5.15.19 | Not specified |
| CNA | Linux | Kernel | affected 5.15.20 | Not specified |
| CNA | Linux | Kernel | affected 5.15.21 | Not specified |
| CNA | Linux | Kernel | affected 5.15.22 | Not specified |
| CNA | Linux | Kernel | affected 5.15.23 | Not specified |
| CNA | Linux | Kernel | affected 5.15.24 | Not specified |
| CNA | Linux | Kernel | affected 5.15.25 | Not specified |
| CNA | Linux | Kernel | affected 5.15.26 | Not specified |
| CNA | Linux | Kernel | affected 5.15.27 | Not specified |
| CNA | Linux | Kernel | affected 5.15.28 | Not specified |
| CNA | Linux | Kernel | affected 5.15.29 | Not specified |
| CNA | Linux | Kernel | affected 5.15.30 | Not specified |
| CNA | Linux | Kernel | affected 5.15.31 | Not specified |
| CNA | Linux | Kernel | affected 5.15.32 | Not specified |
| CNA | Linux | Kernel | affected 5.15.33 | Not specified |
| CNA | Linux | Kernel | affected 5.15.34 | Not specified |
| CNA | Linux | Kernel | affected 5.15.35 | Not specified |
| CNA | Linux | Kernel | affected 5.15.36 | Not specified |
| CNA | Linux | Kernel | affected 5.15.37 | Not specified |
| CNA | Linux | Kernel | affected 5.15.38 | Not specified |
| CNA | Linux | Kernel | affected 5.15.39 | Not specified |
| CNA | Linux | Kernel | affected 5.15.40 | Not specified |
| CNA | Linux | Kernel | affected 5.15.41 | Not specified |
| CNA | Linux | Kernel | affected 5.15.42 | Not specified |
| CNA | Linux | Kernel | affected 5.15.43 | Not specified |
| CNA | Linux | Kernel | affected 5.15.44 | Not specified |
| CNA | Linux | Kernel | affected 5.15.45 | Not specified |
| CNA | Linux | Kernel | affected 5.15.46 | Not specified |
| CNA | Linux | Kernel | affected 5.15.47 | Not specified |
| CNA | Linux | Kernel | affected 5.15.48 | Not specified |
| CNA | Linux | Kernel | affected 5.15.49 | Not specified |
| CNA | Linux | Kernel | affected 5.15.50 | Not specified |
| CNA | Linux | Kernel | affected 5.15.51 | Not specified |
| CNA | Linux | Kernel | affected 5.15.52 | Not specified |
| CNA | Linux | Kernel | affected 5.15.53 | Not specified |
| CNA | Linux | Kernel | affected 5.15.54 | Not specified |
| CNA | Linux | Kernel | affected 5.15.55 | Not specified |
| CNA | Linux | Kernel | affected 5.15.56 | Not specified |
| CNA | Linux | Kernel | affected 5.15.57 | Not specified |
| CNA | Linux | Kernel | affected 5.15.58 | Not specified |
| CNA | Linux | Kernel | affected 5.15.59 | Not specified |
| CNA | Linux | Kernel | affected 5.15.60 | Not specified |
| CNA | Linux | Kernel | affected 5.15.61 | Not specified |
| CNA | Linux | Kernel | affected 5.15.62 | Not specified |
| CNA | Linux | Kernel | affected 5.15.63 | Not specified |
| CNA | Linux | Kernel | affected 5.15.64 | Not specified |
| CNA | Linux | Kernel | affected 5.15.65 | Not specified |
| CNA | Linux | Kernel | affected 5.15.66 | Not specified |
| CNA | Linux | Kernel | affected 5.15.67 | Not specified |
| CNA | Linux | Kernel | affected 5.15.68 | Not specified |
| CNA | Linux | Kernel | affected 5.15.69 | Not specified |
| CNA | Linux | Kernel | affected 5.15.70 | Not specified |
| CNA | Linux | Kernel | affected 5.15.71 | Not specified |
| CNA | Linux | Kernel | affected 5.15.72 | Not specified |
| CNA | Linux | Kernel | affected 5.15.73 | Not specified |
| CNA | Linux | Kernel | affected 5.15.74 | Not specified |
| CNA | Linux | Kernel | affected 5.15.75 | Not specified |
| CNA | Linux | Kernel | affected 5.15.76 | Not specified |
| CNA | Linux | Kernel | affected 5.15.77 | Not specified |
| CNA | Linux | Kernel | affected 5.15.78 | Not specified |
| CNA | Linux | Kernel | affected 5.15.79 | Not specified |
| CNA | Linux | Kernel | affected 5.15.80 | Not specified |
| CNA | Linux | Kernel | affected 5.15.81 | Not specified |
| CNA | Linux | Kernel | affected 5.15.82 | Not specified |
| CNA | Linux | Kernel | affected 5.15.83 | Not specified |
| CNA | Linux | Kernel | affected 5.15.84 | Not specified |
| CNA | Linux | Kernel | affected 5.15.85 | Not specified |
| CNA | Linux | Kernel | affected 6.0.0 | Not specified |
| CNA | Linux | Kernel | affected 6.0.1 | Not specified |
| CNA | Linux | Kernel | affected 6.0.2 | Not specified |
| CNA | Linux | Kernel | affected 6.0.3 | Not specified |
| CNA | Linux | Kernel | affected 6.0.4 | Not specified |
| CNA | Linux | Kernel | affected 6.0.5 | Not specified |
| CNA | Linux | Kernel | affected 6.0.6 | Not specified |
| CNA | Linux | Kernel | affected 6.0.7 | Not specified |
| CNA | Linux | Kernel | affected 6.0.8 | Not specified |
| CNA | Linux | Kernel | affected 6.0.9 | Not specified |
| CNA | Linux | Kernel | affected 6.0.10 | Not specified |
| CNA | Linux | Kernel | affected 6.0.11 | Not specified |
| CNA | Linux | Kernel | affected 6.0.12 | Not specified |
| CNA | Linux | Kernel | affected 6.0.13 | Not specified |
| CNA | Linux | Kernel | affected 6.0.14 | Not specified |
| CNA | Linux | Kernel | affected 6.0.15 | Not specified |
| CNA | Linux | Kernel | affected 6.1.0 | Not specified |
| CNA | Linux | Kernel | affected 6.1.1 | Not specified |
| CNA | Linux | Kernel | unaffected 5.10.163 | Not specified |
| CNA | Linux | Kernel | unaffected 5.15.86 | Not specified |
| CNA | Linux | Kernel | unaffected 6.0.16 | Not specified |
| CNA | Linux | Kernel | unaffected 6.1.2 | Not specified |
| CNA | Linux | Kernel | unaffected 6.2 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| kernel/git/bpf/bpf-next.git - BPF next kernel tree | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | Patch, Vendor Advisory |
| CVE-2022-3534 | Linux Kernel libbpf btf_dump.c btf_dump_name_dups use after free | af854a3a-2127-422b-91ae-364da2661108 | vuldb.com | Permissions Required, Third Party Advisory |
| lists.debian.org/debian-lts-announce/2025/04/msg00033.html | af854a3a-2127-422b-91ae-364da2661108 | lists.debian.org | |
| vuldb.com/cve/CVE-2022-3534 | [email protected] | vuldb.com | |
| vuldb.com/vuln/211032/cti | [email protected] | vuldb.com | |
| www.kernel.org | [email protected] | www.kernel.org | |
| vuldb.com/vuln/211032 | [email protected] | vuldb.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| CNA | 2022-10-17T00:00:00.000Z | Advisory disclosed |
| CNA | 2022-10-17T00:00:00.000Z | CVE reserved |
| CNA | 2022-10-17T02:00:00.000Z | VulDB entry created |
| CNA | 2026-07-28T19:02:04.000Z | VulDB entry last update |
Legacy QID Mappings
- 199062 Ubuntu Security Notification for LibBPF Vulnerabilities (USN-5759-1)
- 199458 Ubuntu Security Notification for dwarves Vulnerabilities (USN-6215-1)
- 354126 Amazon Linux Security Advisory for libbpf : ALAS2-2022-1889
- 355199 Amazon Linux Security Advisory for kernel : ALAS2023-2023-070
- 377891 Alibaba Cloud Linux Security Update for cloud-kernel (ALINUX3-SA-2023:0002)
- 378468 Alibaba Cloud Linux Security Update for cloud-kernel (ALINUX3-SA-20230042)
- 378512 Alibaba Cloud Linux Security Update for cloud-kernel (ALINUX3-SA-2023:0042)
- 6140193 AWS Bottlerocket Security Update for kernel (GHSA-47wc-f242-gvmj)
- 672495 EulerOS Security Update for kernel (EulerOS-SA-2023-1012)
- 672516 EulerOS Security Update for kernel (EulerOS-SA-2023-1037)
- 753691 SUSE Enterprise Linux Security Update for libbpf (SUSE-SU-2023:0405-1)