CVE-2022-3636

Severity
7.8HIGH
EPSS
0.0%
top 93.73%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 21

Description

A vulnerability, which was classified as critical, was found in Linux Kernel. This affects the function __mtk_ppe_check_skb of the file drivers/net/ethernet/mediatek/mtk_ppe.c of the component Ethernet Handler. The manipulation leads to use after free. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-211935.

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:LExploitability: 2.1 | Impact: 3.4

Affected Packages1 packages

CVEListV5linux/kerneln/a

Also affects: Debian Linux 11.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-wp33-7frp-g7vg: A vulnerability, which was classified as critical, was found in Linux Kernel2022-10-21
CVEList
Linux Kernel Ethernet mtk_ppe.c __mtk_ppe_check_skb use after free2022-10-21
OSV
CVE-2022-3636: A vulnerability, which was classified as critical, was found in Linux Kernel2022-10-21

📋Vendor Advisories

2
Red Hat
Kernel: A use after free in __mtk_ppe_check_skb in drivers/net/ethernet/mediatek/mtk_ppe.c2022-04-12
Debian
CVE-2022-3636: linux - A vulnerability, which was classified as critical, was found in Linux Kernel. Th...2022
CVE-2022-3636 (HIGH CVSS 7.8) | A vulnerability | cvebase.io