CVE-2022-2078Stack-based Buffer Overflow in Kernel

Severity
5.5MEDIUMNVD
EPSS
0.5%
top 34.25%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 30
Latest updateJul 21

Description

A vulnerability was found in the Linux kernel's nft_set_desc_concat_parse() function .This flaw allows an attacker to trigger a buffer overflow via nft_set_desc_concat_parse() , causing a denial of service and possibly to run code.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages4 packages

NVDlinux/linux_kernel< 5.19
Debianlinux/linux_kernel< 5.10.120-1+3
CVEListV5linux/linux_kernelkernel 5.19 rc1

Also affects: Debian Linux 11.0, Enterprise Linux 8.0, 9.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-j976-mwc8-7r2m: A vulnerability was found in the Linux kernel's nft_set_desc_concat_parse() function2022-07-01
OSV
CVE-2022-2078: A vulnerability was found in the Linux kernel's nft_set_desc_concat_parse() function2022-06-30
CVEList
CVE-2022-2078: A vulnerability was found in the Linux kernel's nft_set_desc_concat_parse() function2022-06-30

📋Vendor Advisories

5
Ubuntu
Linux kernel (OEM) vulnerabilities2022-07-21
Microsoft
A vulnerability was found in the Linux kernel's nft_set_desc_concat_parse() function .This flaw allows an attacker to trigger a buffer overflow via nft_set_desc_concat_parse() causing a denial of ser2022-06-14
Red Hat
kernel: out-of-bounds write vulnerability in nftable may lead to local privilege escalation2022-06-02
Red Hat
kernel: buffer overflow in nft_set_desc_concat_parse()2022-05-31
Debian
CVE-2022-2078: linux - A vulnerability was found in the Linux kernel's nft_set_desc_concat_parse() func...2022
CVE-2022-2078 — Stack-based Buffer Overflow in Kernel | cvebase