cbcvebase.
CVE-2022-3625
published 2022-10-21

CVE-2022-3625: A vulnerability was found in Linux Kernel. It has been classified as critical. This affects the function devlink_param_set/devlink_param_get of the file…

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
A vulnerability was found in Linux Kernel. It has been classified as critical. This affects the function devlink_param_set/devlink_param_get of the file net/core/devlink.c of the component IPsec. The manipulation leads to use after free. It is recommended to apply a patch to fix this issue. The identifier VDB-211929 was assigned to this vulnerability.

Affected

18 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 5.19.6-1 (bookworm)linux 5.19.6-1 (bookworm)
linuxkernel
linuxlinux_kernel>= 0 < 5.10.140-15.10.140-1
linuxlinux_kernel>= 0 < 5.19.6-15.19.6-1
linuxlinux_kernel>= 0 < 5.19.6-15.19.6-1
linuxlinux_kernel>= 0 < 5.19.6-15.19.6-1
linuxlinux_kernel>= 0 < 5.4.0-132.1485.4.0-132.148
linuxlinux_kernel>= 0 < 5.15.0-53.595.15.0-53.59
linuxlinux_kernel>= 4.19 < 5.4.2115.4.211
linuxlinux_kernel>= 5.11 < 5.15.635.15.63
linuxlinux_kernel>= 5.16 < 5.19.45.19.4
linuxlinux_kernel>= 5.5 < 5.10.1385.10.138
paloaltopan-os
ubuntulinux-gcp-5.15
ubuntulinux-gke-5.15
ubuntulinux-intel-iotg
ubuntulinux-raspi

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH