cbcvebase.
CVE-2022-4378
published 2023-01-05

CVE-2022-4378: A stack overflow flaw was found in the Linux kernel's SYSCTL subsystem in how a user changes certain kernel parameters and variables. This flaw allows a local…

PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.43%
34.9th percentile
A stack overflow flaw was found in the Linux kernel's SYSCTL subsystem in how a user changes certain kernel parameters and variables. This flaw allows a local user to crash or potentially escalate their privileges on the system.

Affected

24 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.0.12-1 (bookworm)linux 6.0.12-1 (bookworm)
gitlabgitlab
gitlabgitlab_ce
googlechrome_chrome
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.158-15.10.158-1
linuxlinux_kernel>= 0 < 6.0.12-16.0.12-1
linuxlinux_kernel>= 0 < 6.0.12-16.0.12-1
linuxlinux_kernel>= 0 < 6.0.12-16.0.12-1
linuxlinux_kernel>= 0 < 4.15.0-206.2174.15.0-206.217
linuxlinux_kernel>= 0 < 5.15.0-58.645.15.0-58.64
linuxlinux_kernel>= 0 < 4.4.0-236.2704.4.0-236.270
linuxlinux_kernel>= 0 < 4.15.0-202.2134.15.0-202.213
linuxlinux_kernel>= 0 < 5.4.0-137.1545.4.0-137.154
linuxlinux_kernel>= 0 < 5.15.0-58.645.15.0-58.64
linuxlinux_kernel4.14.0 – 4.14.302
linuxlinux_kernel4.19.0 – 4.19.269
linuxlinux_kernel4.9.0 – 4.9.337
linuxlinux_kernel5.10.0 – 5.10.162
linuxlinux_kernel5.15.0 – 5.15.86
linuxlinux_kernel5.4.0 – 5.4.228
linuxlinux_kernel6.0.0 – 6.0.11
msrccm1_kernel_5.10.164.1-1_on_cbl_mariner_1.0
paloaltopan-os

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.0HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.