CVE-2022-0500
🟡 Monitoruj
Błąd w eBPF w jądrze Linux umożliwia lokalnemu użytkownikowi eskalację uprawnień lub awarię systemu.
CVSS
7.8
EPSS
0.4%
Exploit
none
Vendor
netapp
Opis źródłowy (NVD)
A flaw was found in unrestricted eBPF usage by the BPF_BTF_LOAD, leading to a possible out-of-bounds memory write in the Linux kernel’s BPF subsystem due to the way a user loads BTF. This flaw allows a local user to crash or escalate their privileges on the system.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 7.8 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.4% |
| Opublikowano (NVD) | 2022-03-25 19:15:10 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-08 22:17:14 UTC |
Referencje
- https://bugzilla.redhat.com/show_bug.cgi?id=2044578 ([email protected]) [Issue Tracking, Third Party Advisory]
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=20b2aff4bc15bda809f994761d5719827d66c0b4 ([email protected]) [Patch, Vendor Advisory]
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=216e3cd2f28dbbf1fe86848e0e29e6693b9f0a20 ([email protected]) [Patch, Vendor Advisory]
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=34d3a78c681e8e7844b43d1a2f4671a04249c821 ([email protected]) [Patch, Vendor Advisory]
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=3c4807322660d4290ac9062c034aed6b87243861 ([email protected]) [Patch, Vendor Advisory]
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=48946bd6a5d695c50b34546864b79c1f910a33c1 ([email protected]) [Patch, Vendor Advisory]
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=c25b2ae136039ffa820c26138ed4a5e5f3ab3841 ([email protected]) [Patch, Vendor Advisory]
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=cf9f2f8d62eca810afbd1ee6cc0800202b000e57 ([email protected]) [Patch, Vendor Advisory]
- https://security.netapp.com/advisory/ntap-20220519-0001/ ([email protected]) [Third Party Advisory]