Lucene search

K
osvGoogleOSV:USN-5390-1
HistoryApr 26, 2022 - 12:59 p.m.

linux, linux-aws, linux-azure, linux-gcp, linux-gke, linux-ibm, linux-kvm, linux-lowlatency vulnerabilities

2022-04-2612:59:37
Google
osv.dev
18
linux kernel
netfilter subsystem
denial of service
arbitrary code
st21nfca nfc driver
sensitive information
cve-2022-1015
cve-2022-1016
cve-2022-26490

AI Score

7.6

Confidence

High

EPSS

0.001

Percentile

19.0%

David Bouman discovered that the netfilter subsystem in the Linux kernel
did not properly validate passed user register indices. A local attacker
could use this to cause a denial of service or possibly execute arbitrary
code. (CVE-2022-1015)

David Bouman discovered that the netfilter subsystem in the Linux kernel
did not initialize memory in some situations. A local attacker could use
this to expose sensitive information (kernel memory). (CVE-2022-1016)

It was discovered that the ST21NFCA NFC driver in the Linux kernel did not
properly validate the size of certain data in EVT_TRANSACTION events. A
physically proximate attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2022-26490)