CVE-2022-3629
published 2022-10-21CVE-2022-3629: A vulnerability was found in Linux Kernel. It has been declared as problematic. This vulnerability affects the function vsock_connect of the file…
PriorityP48low3.3CVSS 3.1
AVLACLPRLUINSUCNINAL
EPSS
0.33%
25.0th percentile
A vulnerability was found in Linux Kernel. It has been declared as problematic. This vulnerability affects the function vsock_connect of the file net/vmw_vsock/af_vsock.c. The manipulation leads to memory leak. The complexity of an attack is rather high. The exploitation appears to be difficult. It is recommended to apply a patch to fix this issue. VDB-211930 is the identifier assigned to this vulnerability.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | linux | < linux 5.19.6-1 (bookworm) | linux 5.19.6-1 (bookworm) |
| linux | kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.140-1 | 5.10.140-1 |
| linux | linux_kernel | >= 0 < 5.19.6-1 | 5.19.6-1 |
| linux | linux_kernel | >= 0 < 5.19.6-1 | 5.19.6-1 |
| linux | linux_kernel | >= 0 < 5.19.6-1 | 5.19.6-1 |
CVSS provenance
nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
nvdv2.01.4LOWAV:A/AC:H/Au:S/C:N/I:N/A:P
osv3.3LOW
vendor_redhat5.9MEDIUM
vendor_debian2.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Linux Kernel net/vmw_vsock/af_vsock.c vsock_connect memory leak (DLA 3173-1 / EUVD-2022-42989)
vuldb·2026-07-18·CVSS 3.3
CVE-2022-3629 [LOW] Linux Kernel net/vmw_vsock/af_vsock.c vsock_connect memory leak (DLA 3173-1 / EUVD-2022-42989)
A vulnerability marked as problematic has been reported in Linux Kernel. This vulnerability affects the function vsock_connect of the file net/vmw_vsock/af_vsock.c. Performing a manipulation results in memory leak.
This vulnerability is cataloged as CVE-2022-3629. The attack must originate from the local network. There is no exploit available.
It is suggested to install a patch to address this issue.
GHSA
GHSA-vwm6-3cgq-cw2w: A vulnerability was found in Linux Kernel
ghsa_unreviewed·2022-10-21
CVE-2022-3629 [LOW] CWE-401 GHSA-vwm6-3cgq-cw2w: A vulnerability was found in Linux Kernel
A vulnerability was found in Linux Kernel. It has been declared as problematic. This vulnerability affects the function vsock_connect of the file net/vmw_vsock/af_vsock.c of the component IPsec. The manipulation leads to memory leak. It is recommended to apply a patch to fix this issue. VDB-211930 is the identifier assigned to this vulnerability.
OSV
CVE-2022-3629: A vulnerability was found in Linux Kernel
osv·2022-10-21·CVSS 3.3
CVE-2022-3629 [LOW] CVE-2022-3629: A vulnerability was found in Linux Kernel
A vulnerability was found in Linux Kernel. It has been declared as problematic. This vulnerability affects the function vsock_connect of the file net/vmw_vsock/af_vsock.c. The manipulation leads to memory leak. The complexity of an attack is rather high. The exploitation appears to be difficult. It is recommended to apply a patch to fix this issue. VDB-211930 is the identifier assigned to this vulnerability.
CISA ICS
Siemens SIMATIC S7-1500 TM MFP Linux Kernel
cisa_ics·2023-06-15·CVSS 5.5
[MEDIUM] Siemens SIMATIC S7-1500 TM MFP Linux Kernel
ICS Advisory
##
Siemens SIMATIC S7-1500 TM MFP Linux Kernel
Release DateJune 15, 2023
Alert CodeICSA-23-166-11
## As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely / low attack complexity / public exploits available
- Vendor: Siemens ProductCERT
- Equipment: SIMATIC S7-1500 TM MFP
- Vulnerabilities: Multiple vulnerabilities
## 2. RISK EVALUATION
Exploitation of these vulnerabilities could lead to denial-of-service, crashing t
Red Hat
kernel: memory leak in the function vsock_connect of Virtual Socket Protocol
vendor_redhat·2022-08-08·CVSS 2.6
CVE-2022-3629 [LOW] CWE-401 kernel: memory leak in the function vsock_connect of Virtual Socket Protocol
kernel: memory leak in the function vsock_connect of Virtual Socket Protocol
A vulnerability was found in Linux Kernel. It has been declared as problematic. This vulnerability affects the function vsock_connect of the file net/vmw_vsock/af_vsock.c. The manipulation leads to memory leak. The complexity of an attack is rather high. The exploitation appears to be difficult. It is recommended to apply a patch to fix this issue. VDB-211930 is the identifier assigned to this vulnerability.
A memory leak flaw was found in the Linux kernel’s Virtual Socket Protocol. This flaw allows a local user to crash the system.
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affec
Red Hat
undertow: potential security issue in flow control over HTTP/2 may lead to DOS(incomplete fix for CVE-2021-3629)
vendor_redhat·2022-04-06·CVSS 5.9
CVE-2022-1259 [MEDIUM] CWE-400 undertow: potential security issue in flow control over HTTP/2 may lead to DOS(incomplete fix for CVE-2021-3629)
undertow: potential security issue in flow control over HTTP/2 may lead to DOS(incomplete fix for CVE-2021-3629)
A flaw was found in Undertow. A potential security issue in flow control handling by the browser over HTTP/2 may cause overhead or a denial of service in the server. This flaw exists because of an incomplete fix for CVE-2021-3629.
A flaw was found in Undertow. A potential security issue in flow control handling by the browser over HTTP/2 may cause overhead or a denial of service in the server.
Statement: This flaw occurs because of an incomplete fix for CVE-2021-3629.
Package: undertow (Red Hat build of Quarkus) - Will not fix
Package: undertow (Red Hat Decision Manager 7) - Not affected
Package: undertow (Red Hat Integration Camel K 1) - Fix deferred
Package: undertow (R
Debian
CVE-2022-3629: linux - A vulnerability was found in Linux Kernel. It has been declared as problematic. ...
vendor_debian·2022·CVSS 2.6
CVE-2022-3629 [LOW] CVE-2022-3629: linux - A vulnerability was found in Linux Kernel. It has been declared as problematic. ...
A vulnerability was found in Linux Kernel. It has been declared as problematic. This vulnerability affects the function vsock_connect of the file net/vmw_vsock/af_vsock.c. The manipulation leads to memory leak. The complexity of an attack is rather high. The exploitation appears to be difficult. It is recommended to apply a patch to fix this issue. VDB-211930 is the identifier assigned to this vulnerability.
Scope: local
bookworm: resolved (fixed in 5.19.6-1)
bullseye: resolved (fixed in 5.10.140-1)
forky: resolved (fixed in 5.19.6-1)
sid: resolved (fixed in 5.19.6-1)
trixie: resolved (fixed in 5.19.6-1)
No detection rules found.
No public exploits indexed.
https://git.kernel.org/pub/scm/linux/kernel/git/klassert/ipsec-next.git/commit/?id=7e97cfed9929eaabc41829c395eb0d1350fccb9dhttps://vuldb.com/?ctiid.211930https://vuldb.com/?id.211930https://git.kernel.org/pub/scm/linux/kernel/git/klassert/ipsec-next.git/commit/?id=7e97cfed9929eaabc41829c395eb0d1350fccb9dhttps://vuldb.com/?ctiid.211930https://vuldb.com/?id.211930
2022-10-21
Published