CVE-2022-3541

Severity
7.8HIGH
EPSS
0.1%
top 73.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 17
Latest updateJan 10

Description

A vulnerability classified as critical has been found in Linux Kernel. This affects the function spl2sw_nvmem_get_mac_address of the file drivers/net/ethernet/sunplus/spl2sw_driver.c of the component BPF. The manipulation leads to use after free. It is recommended to apply a patch to fix this issue. The identifier VDB-211041 was assigned to this vulnerability.

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:LExploitability: 2.1 | Impact: 3.4

Affected Packages3 packages

NVDlinux/linux_kernel5.195.19.17+1
CVEListV5linux/kerneln/a
Debianlinux< 6.0.3-1+2

Patches

🔴Vulnerability Details

3
OSV
CVE-2022-3541: A vulnerability classified as critical has been found in Linux Kernel2022-10-17
CVEList
Linux Kernel BPF spl2sw_driver.c spl2sw_nvmem_get_mac_address use after free2022-10-17
GHSA
GHSA-mhhv-2rpc-5pwq: A vulnerability classified as critical has been found in Linux Kernel2022-10-17

📋Vendor Advisories

7
Ubuntu
Linux kernel (IBM) vulnerabilities2023-01-10
Ubuntu
Linux kernel vulnerabilities2023-01-10
Ubuntu
Linux kernel (Azure) vulnerabilities2023-01-09
Ubuntu
Linux kernel vulnerabilities2023-01-06
Microsoft
Linux Kernel BPF spl2sw_driver.c spl2sw_nvmem_get_mac_address use after free2022-10-11
CVE-2022-3541 (HIGH CVSS 7.8) | A vulnerability classified as criti | cvebase.io