Lucene search

K
nvd[email protected]NVD:CVE-2022-2905
HistorySep 09, 2022 - 3:15 p.m.

CVE-2022-2905

2022-09-0915:15:10
CWE-125
web.nvd.nist.gov
linux
bpf
memory read

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

0.0004 Low

EPSS

Percentile

5.1%

An out-of-bounds memory read flaw was found in the Linux kernel’s BPF subsystem in how a user calls the bpf_tail_call function with a key larger than the max_entries of the map. This flaw allows a local user to gain unauthorized access to data.

Affected configurations

NVD
Node
linuxlinux_kernelRange<6.0
OR
linuxlinux_kernelMatch6.0rc1
OR
linuxlinux_kernelMatch6.0rc2
OR
linuxlinux_kernelMatch6.0rc3
Node
redhatenterprise_linuxMatch8.0
Node
debiandebian_linuxMatch10.0

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

0.0004 Low

EPSS

Percentile

5.1%