CVE-2022-23222
published 2022-01-14CVE-2022-23222: kernel/bpf/verifier.c in the Linux kernel through 5.15.14 allows local users to gain privileges because of the availability of pointer arithmetic via certain…
PriorityP348high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
1.90%
77.5th percentile
kernel/bpf/verifier.c in the Linux kernel through 5.15.14 allows local users to gain privileges because of the availability of pointer arithmetic via certain *_OR_NULL pointer types.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | linux | < linux 5.15.15-1 (bookworm) | linux 5.15.15-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| linux | linux_kernel | >= 0 < 5.10.92-1 | 5.10.92-1 |
| linux | linux_kernel | >= 0 < 5.15.15-1 | 5.15.15-1 |
| linux | linux_kernel | >= 0 < 5.15.15-1 | 5.15.15-1 |
| linux | linux_kernel | >= 0 < 5.15.15-1 | 5.15.15-1 |
| linux | linux_kernel | >= 5.16 < 5.16.11 | 5.16.11 |
| linux | linux_kernel | >= 5.8.0 < 5.15.37 | 5.15.37 |
| msrc | cbl2_kernel_5.15.18.1-1_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2022-23222: In kernel/bpf/verifier
osv·2022-06-01
CVE-2022-23222 CVE-2022-23222: In kernel/bpf/verifier
In kernel/bpf/verifier.c , there is a possible way to manipulate pointer arithmetic due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
OSV
linux-azure-5.13, linux-oracle-5.13 vulnerabilities
osv·2022-04-06·CVSS 6.5
CVE-2022-23222 [MEDIUM] linux-azure-5.13, linux-oracle-5.13 vulnerabilities
linux-azure-5.13, linux-oracle-5.13 vulnerabilities
It was discovered that the BPF verifier in the Linux kernel did not
properly restrict pointer types in certain situations. A local attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2022-23222)
It was discovered that the network traffic control implementation in the
Linux kernel contained a use-after-free vulnerability. A local attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2022-1055)
Yiqi Sun and Kevin Wang discovered that the cgroups implementation in the
Linux kernel did not properly restrict access to the cgroups v1
release_agent feature. A local attacker could use this to gain
administrative privileges. (CVE-2022
OSV
linux-intel-5.13 vulnerabilities
osv·2022-04-01·CVSS 6.5
CVE-2022-25636 [MEDIUM] linux-intel-5.13 vulnerabilities
linux-intel-5.13 vulnerabilities
Nick Gregory discovered that the Linux kernel incorrectly handled network
offload functionality. A local attacker could use this to cause a denial of
service or possibly execute arbitrary code. (CVE-2022-25636)
Enrico Barberis, Pietro Frigo, Marius Muench, Herbert Bos, and Cristiano
Giuffrida discovered that hardware mitigations added by ARM to their
processors to address Spectre-BTI were insufficient. A local attacker could
potentially use this to expose sensitive information. (CVE-2022-23960)
It was discovered that the BPF verifier in the Linux kernel did not
properly restrict pointer types in certain situations. A local attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2022-23222)
Max Kellerm
OSV
linux, linux-aws, linux-aws-5.13, linux-gcp, linux-gcp-5.13, linux-hwe-5.13, linux-kvm, linux-oracle, linux-raspi vulnerabilities
osv·2022-03-22·CVSS 6.5
CVE-2022-23222 [MEDIUM] linux, linux-aws, linux-aws-5.13, linux-gcp, linux-gcp-5.13, linux-hwe-5.13, linux-kvm, linux-oracle, linux-raspi vulnerabilities
linux, linux-aws, linux-aws-5.13, linux-gcp, linux-gcp-5.13, linux-hwe-5.13, linux-kvm, linux-oracle, linux-raspi vulnerabilities
It was discovered that the BPF verifier in the Linux kernel did not
properly restrict pointer types in certain situations. A local attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2022-23222)
Yiqi Sun and Kevin Wang discovered that the cgroups implementation in the
Linux kernel did not properly restrict access to the cgroups v1
release_agent feature. A local attacker could use this to gain
administrative privileges. (CVE-2022-0492)
Jürgen Groß discovered that the Xen subsystem within the Linux kernel did
not adequately limit the number of events driver domains (unprivileged PV
backends) could send to
OSV
linux-oem-5.14 vulnerabilities
osv·2022-02-09·CVSS 4.7
CVE-2022-24122 [MEDIUM] linux-oem-5.14 vulnerabilities
linux-oem-5.14 vulnerabilities
It was discovered that the rlimit tracking for user namespaces in the Linux
kernel did not properly perform reference counting, leading to a use-after-
free vulnerability. A local attacker could use this to cause a denial of
service or possibly execute arbitrary code. (CVE-2022-24122)
It was discovered that the BPF verifier in the Linux kernel did not
properly restrict pointer types in certain situations. A local attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2022-23222)
Jeremy Cline discovered a use-after-free in the nouveau graphics driver of
the Linux kernel during device removal. A privileged or physically
proximate attacker could use this to cause a denial of service (system
crash). (CVE-20
GHSA
GHSA-jjwq-78g3-m34w: kernel/bpf/verifier
ghsa_unreviewed·2022-01-15
CVE-2022-23222 [HIGH] CWE-476 GHSA-jjwq-78g3-m34w: kernel/bpf/verifier
kernel/bpf/verifier.c in the Linux kernel through 5.15.14 allows local users to gain privileges because of the availability of pointer arithmetic via certain *_OR_NULL pointer types.
OSV
CVE-2022-23222: kernel/bpf/verifier
osv·2022-01-14·CVSS 7.8
CVE-2022-23222 [HIGH] CVE-2022-23222: kernel/bpf/verifier
kernel/bpf/verifier.c in the Linux kernel through 5.15.14 allows local users to gain privileges because of the availability of pointer arithmetic via certain *_OR_NULL pointer types.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2022-04-06·CVSS 6.5
CVE-2021-28713 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the BPF verifier in the Linux kernel did not
properly restrict pointer types in certain situations. A local attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2022-23222)
It was discovered that the network traffic control implementation in the
Linux kernel contained a use-after-free vulnerability. A local attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2022-1055)
Yiqi Sun and Kevin Wang discovered that the cgroups implementation in the
Linux kernel did not properly restrict access to the cgroups v1
release_agent feature. A local attacker could use
Ubuntu
Linux kernel (Intel IOTG) vulnerabilities
vendor_ubuntu·2022-04-01·CVSS 6.5
CVE-2022-0742 [MEDIUM] Linux kernel (Intel IOTG) vulnerabilities
Title: Linux kernel (Intel IOTG) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Nick Gregory discovered that the Linux kernel incorrectly handled network
offload functionality. A local attacker could use this to cause a denial of
service or possibly execute arbitrary code. (CVE-2022-25636)
Enrico Barberis, Pietro Frigo, Marius Muench, Herbert Bos, and Cristiano
Giuffrida discovered that hardware mitigations added by ARM to their
processors to address Spectre-BTI were insufficient. A local attacker could
potentially use this to expose sensitive information. (CVE-2022-23960)
It was discovered that the BPF verifier in the Linux kernel did not
properly restrict pointer types in certain situations. A local attacker
could use this to cause a denial of servic
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2022-03-22·CVSS 6.5
CVE-2021-45480 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the BPF verifier in the Linux kernel did not
properly restrict pointer types in certain situations. A local attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2022-23222)
Yiqi Sun and Kevin Wang discovered that the cgroups implementation in the
Linux kernel did not properly restrict access to the cgroups v1
release_agent feature. A local attacker could use this to gain
administrative privileges. (CVE-2022-0492)
Jürgen Groß discovered that the Xen subsystem within the Linux kernel did
not adequately limit the number of events driver domains (unprivileged PV
backends) could send to other guest VMs. An attacke
Ubuntu
Linux kernel (OEM) vulnerabilities
vendor_ubuntu·2022-02-09·CVSS 4.7
CVE-2022-23222 [MEDIUM] Linux kernel (OEM) vulnerabilities
Title: Linux kernel (OEM) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the rlimit tracking for user namespaces in the Linux
kernel did not properly perform reference counting, leading to a use-after-
free vulnerability. A local attacker could use this to cause a denial of
service or possibly execute arbitrary code. (CVE-2022-24122)
It was discovered that the BPF verifier in the Linux kernel did not
properly restrict pointer types in certain situations. A local attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2022-23222)
Jeremy Cline discovered a use-after-free in the nouveau graphics driver of
the Linux kernel during device removal. A privileged or physically
proximate
Red Hat
kernel: local privileges escalation in kernel/bpf/verifier.c
vendor_redhat·2022-01-14·CVSS 7.8
CVE-2022-23222 [HIGH] CWE-763 kernel: local privileges escalation in kernel/bpf/verifier.c
kernel: local privileges escalation in kernel/bpf/verifier.c
kernel/bpf/verifier.c in the Linux kernel through 5.15.14 allows local users to gain privileges because of the availability of pointer arithmetic via certain *_OR_NULL pointer types.
A flaw was found in the Linux kernel's adjust_ptr_min_max_vals in the kernel/bpf/verifier.c function. In this flaw, a missing sanity check for *_OR_NULL pointer types that perform pointer arithmetic may cause a kernel information leak issue.
Statement: The default Red Hat Enterprise Linux kernel prevents unprivileged users from being able to use eBPF by the kernel.unprivileged_bpf_disabled sysctl.
This would require a privileged user with CAP_SYS_ADMIN or root to be able to abuse this flaw reducing its attack space.
For the Red Hat Enterprise Linu
Microsoft
kernel/bpf/verifier.c in the Linux kernel through 5.15.14 allows local users to gain privileges because of the availability of pointer arithmetic via certain *_OR_NULL pointer types.
vendor_msrc·2022-01-11·CVSS 7.8
CVE-2022-23222 [HIGH] CWE-476 kernel/bpf/verifier.c in the Linux kernel through 5.15.14 allows local users to gain privileges because of the availability of pointer arithmetic via certain *_OR_NULL pointer types.
kernel/bpf/verifier.c in the Linux kernel through 5.15.14 allows local users to gain privileges because of the availability of pointer arithmetic via certain *_OR_NULL pointer types.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect th
Debian
CVE-2022-23222: linux - kernel/bpf/verifier.c in the Linux kernel through 5.15.14 allows local users to ...
vendor_debian·2022·CVSS 7.8
CVE-2022-23222 [HIGH] CVE-2022-23222: linux - kernel/bpf/verifier.c in the Linux kernel through 5.15.14 allows local users to ...
kernel/bpf/verifier.c in the Linux kernel through 5.15.14 allows local users to gain privileges because of the availability of pointer arithmetic via certain *_OR_NULL pointer types.
Scope: local
bookworm: resolved (fixed in 5.15.15-1)
bullseye: resolved (fixed in 5.10.92-1)
forky: resolved (fixed in 5.15.15-1)
sid: resolved (fixed in 5.15.15-1)
trixie: resolved (fixed in 5.15.15-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2022-0500 kernel: Linux ebpf logic vulnerability leads to critical memory read and write gaining root privileges
bugzilla·2022-01-24·CVSS 7.8
CVE-2022-0500 [HIGH] CVE-2022-0500 kernel: Linux ebpf logic vulnerability leads to critical memory read and write gaining root privileges
CVE-2022-0500 kernel: Linux ebpf logic vulnerability leads to critical memory read and write gaining root privileges
Linux ebpf logic vulnerability leads to critical memory read and write,An attacker with cap_bpf can gain root privileges or container escape.
References:
https://bugzilla.redhat.com/show_bug.cgi?id=2040599
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2056248]
---
Hi Pedro
The information is quite scarce here to determine which kernel versions are affected by the issue. Can you point to the upstream fix in 5.17-rc1 which fixes the issue? I'm interested to correctly track this CVE in another downstream distribution.
Many thanks already!
Regards,
Salvatore
---
In reply to comment #10:
> Hi Pedro
>
> The information is quite scar
Bugzilla
CVE-2022-23222 kernel: local privileges escalation in kernel/bpf/verifier.c
bugzilla·2022-01-21·CVSS 7.8
CVE-2022-23222 [HIGH] CVE-2022-23222 kernel: local privileges escalation in kernel/bpf/verifier.c
CVE-2022-23222 kernel: local privileges escalation in kernel/bpf/verifier.c
Local privileges escalation possible because of the availability of pointer arithmetic via certain *_OR_NULL pointer types in kernel/bpf/verifier.c.
Reference:
https://www.openwall.com/lists/oss-security/2022/01/13/1
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2043521]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8.6 Extended Update Support
Via RHSA-2024:0724 https://access.redhat.com/errata/RHSA-2024:0724
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:2950 https://access.redhat.com/errata/RHSA-2024:2950
---
This issue has been addressed in the following products:
Re
http://www.openwall.com/lists/oss-security/2022/01/14/1http://www.openwall.com/lists/oss-security/2022/01/18/2http://www.openwall.com/lists/oss-security/2022/06/01/1http://www.openwall.com/lists/oss-security/2022/06/04/3http://www.openwall.com/lists/oss-security/2022/06/07/3https://bugzilla.suse.com/show_bug.cgi?id=1194765https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=64620e0a1e712a778095bd35cbb277dc2259281fhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FCR3LIRUEXR7CA63W5M2HT3K63MZGKBR/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z5VTIZZUPC73IEJNZX66BY2YCBRZAELB/https://security.netapp.com/advisory/ntap-20220217-0002/https://www.debian.org/security/2022/dsa-5050https://www.openwall.com/lists/oss-security/2022/01/13/1http://www.openwall.com/lists/oss-security/2022/01/14/1http://www.openwall.com/lists/oss-security/2022/01/18/2http://www.openwall.com/lists/oss-security/2022/06/01/1http://www.openwall.com/lists/oss-security/2022/06/04/3http://www.openwall.com/lists/oss-security/2022/06/07/3https://bugzilla.suse.com/show_bug.cgi?id=1194765https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=64620e0a1e712a778095bd35cbb277dc2259281fhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FCR3LIRUEXR7CA63W5M2HT3K63MZGKBR/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z5VTIZZUPC73IEJNZX66BY2YCBRZAELB/https://security.netapp.com/advisory/ntap-20220217-0002/https://www.debian.org/security/2022/dsa-5050https://www.openwall.com/lists/oss-security/2022/01/13/1
2022-01-14
Published