CVE-2022-0998 — Integer Overflow or Wraparound in Kernel
Severity
7.8HIGHNVD
EPSS
0.2%
top 63.75%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 30
Latest updateMar 31
Description
An integer overflow flaw was found in the Linux kernel’s virtio device driver code in the way a user triggers the vhost_vdpa_config_validate function. This flaw allows a local user to crash or potentially escalate their privileges on the system.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9
Affected Packages10 packages
Patches
🔴Vulnerability Details
2GHSA▶
GHSA-fhq6-983r-j5mh: An integer overflow flaw was found in the Linux kernel’s virtio device driver code in the way a user triggers the vhost_vdpa_config_validate function↗2022-03-31
OSV▶
CVE-2022-0998: An integer overflow flaw was found in the Linux kernel’s virtio device driver code in the way a user triggers the vhost_vdpa_config_validate function↗2022-03-30
📋Vendor Advisories
3Microsoft▶
An integer overflow flaw was found in the Linux kernel’s virtio device driver code in the way a user triggers the vhost_vdpa_config_validate function. This flaw allows a local user to crash or potenti↗2022-03-08
Red Hat▶
kernel: an integer overflow in the vhost_vdpa_config_validate() can lead to out-of-bounds access on top of a 32-bit Linux kernel↗2022-01-22
Debian▶
CVE-2022-0998: linux - An integer overflow flaw was found in the Linux kernel’s virtio device driver co...↗2022