Lucene search

K
ubuntucveUbuntu.comUB:CVE-2022-20567
HistoryDec 16, 2022 - 12:00 a.m.

CVE-2022-20567

2022-12-1600:00:00
ubuntu.com
ubuntu.com
23
pppol2tp_create
l2tp_ppp.c
local privilege escalation
android kernel
race condition
use after free
system execution privileges
bugzilla
upstream kernel

6.4 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

0.0004 Low

EPSS

Percentile

5.1%

In pppol2tp_create of l2tp_ppp.c, there is a possible use after free due to
a race condition. This could lead to local escalation of privilege with
System execution privileges needed. User interaction is not needed for
exploitation.Product: AndroidVersions: Android kernelAndroid ID:
A-186777253References: Upstream kernel

Bugs

OSVersionArchitecturePackageVersionFilename
ubuntu16.04noarchlinux< 4.4.0-252.286UNKNOWN
ubuntu14.04noarchlinux-aws< 4.4.0-1129.135UNKNOWN
ubuntu16.04noarchlinux-aws< 4.4.0-1167.182UNKNOWN
ubuntu24.04noarchlinux-gke< anyUNKNOWN
ubuntu16.04noarchlinux-kvm< 4.4.0-1130.140UNKNOWN
ubuntu14.04noarchlinux-lts-xenial< 4.4.0-252.286~14.04.1UNKNOWN

6.4 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

0.0004 Low

EPSS

Percentile

5.1%