CVE-2022-3633
published 2022-10-21CVE-2022-3633: A vulnerability classified as problematic has been found in Linux Kernel. Affected is the function j1939_session_destroy of the file net/can/j1939/transport.c…
PriorityP47low3.3CVSS 3.1
AVLACLPRLUINSUCNINAL
EPSS
0.30%
22.1th percentile
A vulnerability classified as problematic has been found in Linux Kernel. Affected is the function j1939_session_destroy of the file net/can/j1939/transport.c. The manipulation leads to memory leak. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211932.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | linux | < linux 5.19.6-1 (bookworm) | linux 5.19.6-1 (bookworm) |
| linux | kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.140-1 | 5.10.140-1 |
| linux | linux_kernel | >= 0 < 5.19.6-1 | 5.19.6-1 |
| linux | linux_kernel | >= 0 < 5.19.6-1 | 5.19.6-1 |
| linux | linux_kernel | >= 0 < 5.19.6-1 | 5.19.6-1 |
CVSS provenance
nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
nvdv2.02.7LOWAV:A/AC:L/Au:S/C:N/I:N/A:P
osv3.3LOW
vendor_debian3.5LOW
vendor_redhat3.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Linux Kernel transport.c j1939_session_destroy memory leak (DLA 3173-1 / EUVD-2022-42993)
vuldb·2026-07-18·CVSS 3.3
CVE-2022-3633 [LOW] Linux Kernel transport.c j1939_session_destroy memory leak (DLA 3173-1 / EUVD-2022-42993)
A vulnerability classified as problematic has been found in Linux Kernel. Impacted is the function j1939_session_destroy of the file net/can/j1939/transport.c. The manipulation leads to memory leak.
This vulnerability is documented as CVE-2022-3633. The attack requires being on the local network. There is not any exploit available.
To fix this issue, it is recommended to deploy a patch.
OSV
CVE-2022-3633: A vulnerability classified as problematic has been found in Linux Kernel
osv·2022-10-21·CVSS 3.3
CVE-2022-3633 [LOW] CVE-2022-3633: A vulnerability classified as problematic has been found in Linux Kernel
A vulnerability classified as problematic has been found in Linux Kernel. Affected is the function j1939_session_destroy of the file net/can/j1939/transport.c. The manipulation leads to memory leak. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211932.
GHSA
GHSA-4h2p-5cf9-5j8f: A vulnerability classified as problematic has been found in Linux Kernel
ghsa_unreviewed·2022-10-21
CVE-2022-3633 [LOW] CWE-401 GHSA-4h2p-5cf9-5j8f: A vulnerability classified as problematic has been found in Linux Kernel
A vulnerability classified as problematic has been found in Linux Kernel. Affected is the function j1939_session_destroy of the file net/can/j1939/transport.c of the component IPsec. The manipulation leads to memory leak. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211932.
CISA ICS
Siemens SIMATIC S7-1500 TM MFP Linux Kernel
cisa_ics·2023-06-15·CVSS 5.5
[MEDIUM] Siemens SIMATIC S7-1500 TM MFP Linux Kernel
ICS Advisory
##
Siemens SIMATIC S7-1500 TM MFP Linux Kernel
Release DateJune 15, 2023
Alert CodeICSA-23-166-11
## As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely / low attack complexity / public exploits available
- Vendor: Siemens ProductCERT
- Equipment: SIMATIC S7-1500 TM MFP
- Vulnerabilities: Multiple vulnerabilities
## 2. RISK EVALUATION
Exploitation of these vulnerabilities could lead to denial-of-service, crashing t
Red Hat
kernel: memory leak in the function j1939_session_destroy for j1939 socket
vendor_redhat·2022-08-05·CVSS 3.5
CVE-2022-3633 [LOW] CWE-401 kernel: memory leak in the function j1939_session_destroy for j1939 socket
kernel: memory leak in the function j1939_session_destroy for j1939 socket
A vulnerability classified as problematic has been found in Linux Kernel. Affected is the function j1939_session_destroy of the file net/can/j1939/transport.c. The manipulation leads to memory leak. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211932.
A memory leak flaw was found in the Linux kernel’s j1939 socket functionality. This flaw allows a local user to crash the system.
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Package: kernel-rt (Red Hat Enterprise L
Debian
CVE-2022-3633: linux - A vulnerability classified as problematic has been found in Linux Kernel. Affect...
vendor_debian·2022·CVSS 3.5
CVE-2022-3633 [LOW] CVE-2022-3633: linux - A vulnerability classified as problematic has been found in Linux Kernel. Affect...
A vulnerability classified as problematic has been found in Linux Kernel. Affected is the function j1939_session_destroy of the file net/can/j1939/transport.c. The manipulation leads to memory leak. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211932.
Scope: local
bookworm: resolved (fixed in 5.19.6-1)
bullseye: resolved (fixed in 5.10.140-1)
forky: resolved (fixed in 5.19.6-1)
sid: resolved (fixed in 5.19.6-1)
trixie: resolved (fixed in 5.19.6-1)
No detection rules found.
No public exploits indexed.
https://git.kernel.org/pub/scm/linux/kernel/git/klassert/ipsec-next.git/commit/?id=8c21c54a53ab21842f5050fa090f26b03c0313d6https://vuldb.com/?ctiid.211932https://vuldb.com/?id.211932https://git.kernel.org/pub/scm/linux/kernel/git/klassert/ipsec-next.git/commit/?id=8c21c54a53ab21842f5050fa090f26b03c0313d6https://vuldb.com/?ctiid.211932https://vuldb.com/?id.211932
2022-10-21
Published