CVE-2022-0322
published 2022-03-25CVE-2022-0322: A flaw was found in the sctp_make_strreset_req function in net/sctp/sm_make_chunk.c in the SCTP network protocol in the Linux kernel with a local user…
PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.29%
21.2th percentile
A flaw was found in the sctp_make_strreset_req function in net/sctp/sm_make_chunk.c in the SCTP network protocol in the Linux kernel with a local user privilege access. In this flaw, an attempt to use more buffer than is allocated triggers a BUG_ON issue, leading to a denial of service (DOS).
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.14.16-1 (bookworm) | linux 5.14.16-1 (bookworm) |
| fedoraproject | fedora | — | — |
| linux | linux_kernel | < 5.15 | 5.15 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.84-1 | 5.10.84-1 |
| linux | linux_kernel | >= 0 < 5.14.16-1 | 5.14.16-1 |
| linux | linux_kernel | >= 0 < 5.14.16-1 | 5.14.16-1 |
| linux | linux_kernel | >= 0 < 5.14.16-1 | 5.14.16-1 |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cm1_kernel_5.10.111.1-1_on_cbl_mariner_1.0 | — | — |
| oracle | communications_cloud_native_core_binding_support_function | — | — |
| oracle | communications_cloud_native_core_network_exposure_function | — | — |
| oracle | communications_cloud_native_core_policy | — | — |
| paloalto | pan-os | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
cisa8.8HIGH
vendor_redhat7.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2024-02-14·CVSS 9.8
CVE-2017-18342 [CRITICAL] PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2017-18342, CVE-2017-8923, CVE-2017-9120, CVE-2019-1551, CVE-2019-16865, CVE-2019-16905, CVE-2019-19523, CVE-2019-19528, CVE-2019-19911, CVE-2020-0404, CVE-2020-0431, CVE-2020-0466, CVE-2020-10379, CVE-2020-11538, CVE-2020-11608, CVE-2020-12114, CVE-2020-12321, CVE-2020-12362, CVE-2020-12363, CVE-2020-12364, CVE-2020-13757, CVE-2020-14314, CVE-2020-14351, CVE-2020-15778, CVE-2020-1967, CVE-2020-24394, CVE-2020-24504, CVE-2020-25211, CVE-2020-25212, CVE-2020-25284, CVE-2020-25285, CVE-2020-25717, CVE-2020-26541, CVE-2020-2715
Red Hat
vim: use after free in function qf_buf_add_line( )
vendor_redhat·2022-08-30·CVSS 7.8
CVE-2022-3037 [HIGH] CWE-416 vim: use after free in function qf_buf_add_line( )
vim: use after free in function qf_buf_add_line( )
Use After Free in GitHub repository vim/vim prior to 9.0.0322.
A flaw was found in vim, where it is vulnerable to a use-after-free in the qf_buf_add_line() function. This flaw allows a specially crafted file to crash a program, use unexpected values, or execute code.
Statement: Red Hat Product Security has rated this issue as having a Low security impact, because the "victim" has to run an untrusted file IN SCRIPT MODE. Someone who is running untrusted files in script mode is equivalent to someone just taking a random python script and running it.
Package: vim (Red Hat Enterprise Linux 6) - Out of support scope
Package: vim (Red Hat Enterprise Linux 7) - Out of support scope
Package: vim (Red Hat Enterprise Linux 8) - Fix deferred
P
CISA
Microsoft Internet Explorer Use-After-Free Vulnerability
cisa·2022-05-04·CVSS 8.8
CVE-2014-0322 [HIGH] CWE-416 Microsoft Internet Explorer Use-After-Free Vulnerability
Vulnerability: Microsoft Internet Explorer Use-After-Free Vulnerability
Affected: Microsoft Internet Explorer
Use-after-free vulnerability in Microsoft Internet Explorer allows remote attackers to execute code.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2014-0322
Remediation Due Date: 2022-05-25
Microsoft
A flaw was found in the sctp_make_strreset_req function in net/sctp/sm_make_chunk.c in the SCTP network protocol in the Linux kernel with a local user privilege access. In this flaw an attempt to use
vendor_msrc·2022-03-08·CVSS 5.5
CVE-2022-0322 [MEDIUM] CWE-704 A flaw was found in the sctp_make_strreset_req function in net/sctp/sm_make_chunk.c in the SCTP network protocol in the Linux kernel with a local user privilege access. In this flaw an attempt to use
A flaw was found in the sctp_make_strreset_req function in net/sctp/sm_make_chunk.c in the SCTP network protocol in the Linux kernel with a local user privilege access. In this flaw an attempt to use more buffer than is allocated triggers a BUG_ON issue leading to a denial of service (DOS).
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog po
Red Hat
kernel: sctp: local DoS: unprivileged user can cause BUG()
vendor_redhat·2022-02-03·CVSS 5.5
CVE-2021-3894 [MEDIUM] CWE-400 kernel: sctp: local DoS: unprivileged user can cause BUG()
kernel: sctp: local DoS: unprivileged user can cause BUG()
A vulnerability was found in the Linux kernel. This flaw allows an unprivileged local user to panic the system, resulting in a denial of service by calling setsockopt(2) with specially crafted arguments. The highest threat from this vulnerability is to system availability.
Statement: This flaw was found to be a duplicate of CVE-2022-0322. Please see https://access.redhat.com/security/cve/CVE-2022-0322 for information about affected products and security errata.
Mitigation: As the SCTP module will be auto-loaded when required, its use can be disabled by preventing the module from loading with the following instructions:
# echo "install sctp /bin/true" >> /etc/modprobe.d/disable-sctp.conf
The system will need to be restarted if th
Debian
CVE-2022-0322: linux - A flaw was found in the sctp_make_strreset_req function in net/sctp/sm_make_chun...
vendor_debian·2022·CVSS 5.5
CVE-2022-0322 [MEDIUM] CVE-2022-0322: linux - A flaw was found in the sctp_make_strreset_req function in net/sctp/sm_make_chun...
A flaw was found in the sctp_make_strreset_req function in net/sctp/sm_make_chunk.c in the SCTP network protocol in the Linux kernel with a local user privilege access. In this flaw, an attempt to use more buffer than is allocated triggers a BUG_ON issue, leading to a denial of service (DOS).
Scope: local
bookworm: resolved (fixed in 5.14.16-1)
bullseye: resolved (fixed in 5.10.84-1)
forky: resolved (fixed in 5.14.16-1)
sid: resolved (fixed in 5.14.16-1)
trixie: resolved (fixed in 5.14.16-1)
Red Hat
kernel: DoS in sctp_addto_chunk in net/sctp/sm_make_chunk.c
vendor_redhat·2021-10-14·CVSS 5.5
CVE-2022-0322 [MEDIUM] CWE-681 kernel: DoS in sctp_addto_chunk in net/sctp/sm_make_chunk.c
kernel: DoS in sctp_addto_chunk in net/sctp/sm_make_chunk.c
A flaw was found in the sctp_make_strreset_req function in net/sctp/sm_make_chunk.c in the SCTP network protocol in the Linux kernel with a local user privilege access. In this flaw, an attempt to use more buffer than is allocated triggers a BUG_ON issue, leading to a denial of service (DOS).
A flaw was found in the sctp_make_strreset_req function in net/sctp/sm_make_chunk.c in the SCTP network protocol in the Linux kernel with a local user privilege access. In this flaw, an attempt to use more buffer than is allocated triggers a BUG_ON issue, leading to a denial of service (DOS).
Mitigation: Mitigation for this issue is to skip loading the affected module SCTP onto the system. Until we have a fix available, this can be done by
GHSA
GHSA-g6mc-765r-fwwj: A flaw was found in the sctp_make_strreset_req function in net/sctp/sm_make_chunk
ghsa_unreviewed·2022-03-26
CVE-2022-0322 [MEDIUM] CWE-704 GHSA-g6mc-765r-fwwj: A flaw was found in the sctp_make_strreset_req function in net/sctp/sm_make_chunk
A flaw was found in the sctp_make_strreset_req function in net/sctp/sm_make_chunk.c in the SCTP network protocol in the Linux kernel with a local user privilege access. In this flaw, an attempt to use more buffer than is allocated triggers a BUG_ON issue, leading to a denial of service (DOS).
OSV
CVE-2022-0322: A flaw was found in the sctp_make_strreset_req function in net/sctp/sm_make_chunk
osv·2022-03-25·CVSS 5.5
CVE-2022-0322 [MEDIUM] CVE-2022-0322: A flaw was found in the sctp_make_strreset_req function in net/sctp/sm_make_chunk
A flaw was found in the sctp_make_strreset_req function in net/sctp/sm_make_chunk.c in the SCTP network protocol in the Linux kernel with a local user privilege access. In this flaw, an attempt to use more buffer than is allocated triggers a BUG_ON issue, leading to a denial of service (DOS).
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=2042822https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=a2d859e3fc97e79d907761550dbc03ff1b36479chttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=2042822https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=a2d859e3fc97e79d907761550dbc03ff1b36479chttps://www.oracle.com/security-alerts/cpujul2022.html
2022-03-25
Published