cbcvebase.
CVE-2022-3534
published 2022-10-17

CVE-2022-3534: A vulnerability has been found in Linux Kernel up to 5.10.162/5.15.85/6.0.15/6.1.1. The impacted element is the function btf_dump_name_dups of the file…

PriorityP343high8CVSS 3.1
AVAACLPRLUINSUCHIHAH
EPSS
0.91%
57.4th percentile
A vulnerability has been found in Linux Kernel up to 5.10.162/5.15.85/6.0.15/6.1.1. The impacted element is the function btf_dump_name_dups of the file tools/lib/bpf/btf_dump.c of the component libbpf. The manipulation leads to use after free. Upgrading to version 5.10.163, 5.15.86, 6.0.16, 6.1.2 and 6.2 is sufficient to resolve this issue. The identifier of the patch is c61650b869e0b6fb0c0a28ed42d928eea969afc8/fbe08093fb2334549859829ef81d42570812597d/8c64a8e76eb85d422af5ec60ccbf26e3ead8c333/a733bf10198eb5bb927890940de8ab457491ed3b/93c660ca40b5d2f7c1b1626e955a8e9fa30e0749. You should upgrade the affected component.

Affected

117 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlibbpf< libbpf 1.1.0-1 (bookworm)libbpf 1.1.0-1 (bookworm)
libbpf_projectlibbpf>= 0 < 0.3-2+deb11u10.3-2+deb11u1
libbpf_projectlibbpf>= 0 < 1.1.0-11.1.0-1
libbpf_projectlibbpf>= 0 < 1.1.0-11.1.0-1
libbpf_projectlibbpf>= 0 < 1.1.0-11.1.0-1
libbpf_projectlibbpf>= 0 < 0.5.0-1ubuntu22.04.10.5.0-1ubuntu22.04.1
libbpf_projectlibbpf>= 0 < 0.5.0-1~ubuntu20.04.1+esm10.5.0-1~ubuntu20.04.1+esm1
linuxkernel
linuxkernel
linuxkernel
linuxkernel
linuxkernel
linuxkernel
linuxkernel
linuxkernel
linuxkernel
linuxkernel
linuxkernel
linuxkernel
linuxkernel
linuxkernel
linuxkernel
linuxkernel
linuxkernel

CVSS provenance

nvdv3.18.0HIGHCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv4.05.1MEDIUMCVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.04.9MEDIUMAV:A/AC:M/Au:S/C:P/I:P/A:P
osv8.0HIGH
vendor_ubuntu6.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.