CVE-2022-0998Integer Overflow or Wraparound in Kernel

Severity
7.8HIGHNVD
EPSS
0.2%
top 63.75%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 30
Latest updateMar 31

Description

An integer overflow flaw was found in the Linux kernel’s virtio device driver code in the way a user triggers the vhost_vdpa_config_validate function. This flaw allows a local user to crash or potentially escalate their privileges on the system.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages10 packages

debiandebian/linux< linux 5.15.15-1 (bookworm)
NVDlinux/linux_kernel5.75.10.88+1
Debianlinux/linux_kernel< 5.10.92-1+3
CVEListV5linux/linux_kernelLinux kernel 5.17-rc1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-fhq6-983r-j5mh: An integer overflow flaw was found in the Linux kernel’s virtio device driver code in the way a user triggers the vhost_vdpa_config_validate function2022-03-31
OSV
CVE-2022-0998: An integer overflow flaw was found in the Linux kernel’s virtio device driver code in the way a user triggers the vhost_vdpa_config_validate function2022-03-30

📋Vendor Advisories

3
Microsoft
An integer overflow flaw was found in the Linux kernel’s virtio device driver code in the way a user triggers the vhost_vdpa_config_validate function. This flaw allows a local user to crash or potenti2022-03-08
Red Hat
kernel: an integer overflow in the vhost_vdpa_config_validate() can lead to out-of-bounds access on top of a 32-bit Linux kernel2022-01-22
Debian
CVE-2022-0998: linux - An integer overflow flaw was found in the Linux kernel’s virtio device driver co...2022