Lucene search

K
osvGoogleOSV:USN-5353-1
HistoryMar 28, 2022 - 11:13 p.m.

linux-oem-5.14 vulnerability

2022-03-2823:13:52
Google
osv.dev
11

7.2 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

It was discovered that the IPsec implementation in the Linux kernel did not
properly allocate enough memory when performing ESP transformations,
leading to a heap-based buffer overflow. A local attacker could use this to
cause a denial of service (system crash) or possibly execute arbitrary
code.