cbcvebase.
CVE-2022-2905
published 2022-09-09

CVE-2022-2905: An out-of-bounds memory read flaw was found in the Linux kernel's BPF subsystem in how a user calls the bpf_tail_call function with a key larger than the…

medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
An out-of-bounds memory read flaw was found in the Linux kernel's BPF subsystem in how a user calls the bpf_tail_call function with a key larger than the max_entries of the map. This flaw allows a local user to gain unauthorized access to data.

Affected

17 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 5.19.6-1 (bookworm)linux 5.19.6-1 (bookworm)
linuxlinux_kernel< 6.06.0
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.140-15.10.140-1
linuxlinux_kernel>= 0 < 5.19.6-15.19.6-1
linuxlinux_kernel>= 0 < 5.19.6-15.19.6-1
linuxlinux_kernel>= 0 < 5.19.6-15.19.6-1
linuxlinux_kernel>= 0 < 5.15.0-53.595.15.0-53.59
msrccbl2_kernel_5.15.70.1-1_on_cbl_mariner_2.0
msrccm1_kernel_5.10.144.1-1_on_cbl_mariner_1.0
redhatenterprise_linux
ubuntulinux-gcp-5.15
ubuntulinux-gke-5.15
ubuntulinux-intel-iotg
ubuntulinux-raspi

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
osv7.0HIGH