Lucene search

K
ubuntucveUbuntu.comUB:CVE-2022-3606
HistoryOct 19, 2022 - 12:00 a.m.

CVE-2022-3606

2022-10-1900:00:00
ubuntu.com
ubuntu.com
12
linux kernel
find_prog_by_sec_insn
bpf
null pointer dereference
patch
vdb-211749
unix

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

0.0004 Low

EPSS

Percentile

12.6%

A vulnerability was found in Linux Kernel. It has been classified as
problematic. This affects the function find_prog_by_sec_insn of the file
tools/lib/bpf/libbpf.c of the component BPF. The manipulation leads to null
pointer dereference. It is recommended to apply a patch to fix this issue.
The identifier VDB-211749 was assigned to this vulnerability.

OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchdwarves-dfsg< 1.21-0ubuntu1~18.04.1+esm1UNKNOWN
ubuntu20.04noarchdwarves-dfsg< 1.21-0ubuntu1~20.04.1UNKNOWN
ubuntu16.04noarchdwarves-dfsg< anyUNKNOWN
ubuntu20.04noarchlibbpf< 0.5.0-1~ubuntu20.04.1+esm1UNKNOWN
ubuntu22.04noarchlibbpf< 0.5.0-1ubuntu22.04.1UNKNOWN
ubuntu22.10noarchlibbpf< 0.8.0-1ubuntu22.10.1UNKNOWN
ubuntu23.04noarchlibbpf< 1.0.1-2ubuntu1UNKNOWN
ubuntu23.10noarchlibbpf< 1.0.1-2ubuntu1UNKNOWN
ubuntu24.04noarchlibbpf< 1.0.1-2ubuntu1UNKNOWN

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

0.0004 Low

EPSS

Percentile

12.6%