cbcvebase.
CVE-2022-3435
published 2022-10-08

CVE-2022-3435: A vulnerability classified as problematic has been found in Linux Kernel. This affects the function fib_nh_match of the file net/ipv4/fib_semantics.c of the…

medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
A vulnerability classified as problematic has been found in Linux Kernel. This affects the function fib_nh_match of the file net/ipv4/fib_semantics.c of the component IPv4 Handler. The manipulation leads to out-of-bounds read. It is possible to initiate the attack remotely. It is recommended to apply a patch to fix this issue. The identifier VDB-210357 was assigned to this vulnerability.

Affected

12 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.0.12-1 (bookworm)linux 6.0.12-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
linuxkernel
linuxlinux_kernel>= 0 < 5.10.158-15.10.158-1
linuxlinux_kernel>= 0 < 6.0.12-16.0.12-1
linuxlinux_kernel>= 0 < 6.0.12-16.0.12-1
linuxlinux_kernel>= 0 < 6.0.12-16.0.12-1
linuxlinux_kernel>= 0 < 5.4.0-144.1615.4.0-144.161
linuxlinux_kernel>= 0 < 5.15.0-67.745.15.0-67.74

CVSS provenance

nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
osv5.5MEDIUM