PT-2022-5942 · Linux+8 · Linux Kernel+8

·

CVE-2022-3028

·

Published

2022-07-21

·

Updated

2023-08-14

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A race condition was found in the Linux kernel's IP framework for transforming packets (XFRM subsystem) when multiple calls to xfrm probe algs occurred simultaneously. This flaw could allow a local attacker to potentially trigger an out-of-bounds write or leak kernel heap memory by performing an out-of-bounds read and copying it into a socket. The vulnerability may also allow an attacker to execute arbitrary code, cause a denial of service, or have other impacts on the system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Improper Locking

Race Condition

Memory Corruption

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2023:2148
ALSA-2023:2458
ALSA-2023:2736
ALSA-2023:2951
ALT-PU-2022-2567
ALT-PU-2022-2573
ALT-PU-2022-2594
ALT-PU-2022-2633
ALT-PU-2022-2634
ALT-PU-2022-2635
ALT-PU-2022-2636
ALT-PU-2022-2641
ALT-PU-2022-2658
ALT-PU-2022-2664
ALT-PU-2022-2676
ALT-PU-2022-2682
ALT-PU-2022-2692
ALT-PU-2022-2915
ALT-PU-2022-2919
ALT-PU-2022-3066
ALT-PU-2023-4894
AZL-10822
BDU:2022-07365
CESA-2023_2736
CESA-2023_2951
CVE-2022-3028
DLA-3131-1
DLA-3173-1
MGASA-2022-0324
MGASA-2022-0380
OESA-2022-1893
OESA-2022-1894
OESA-2022-1895
OPENSUSE-SU-2022_3264-1
OPENSUSE-SU-2022_3288-1
OPENSUSE-SU-2022_3293-1
OPENSUSE-SU-2022_3408-1
OPENSUSE-SU-2022_3609-1
OPENSUSE-SU-2022_4617-1
RHSA-2023:2148
RHSA-2023:2458
RHSA-2023:2736
RHSA-2023:2951
RHSA-2023_2148
RHSA-2023_2458
RHSA-2023_2736
RHSA-2023_2951
RHSA-2024:0412
SUSE-SU-2022:3263-1
SUSE-SU-2022:3264-1
SUSE-SU-2022:3265-1
SUSE-SU-2022:3274-1
SUSE-SU-2022:3282-1
SUSE-SU-2022:3288-1
SUSE-SU-2022:3291-1
SUSE-SU-2022:3293-1
SUSE-SU-2022:3294-1
SUSE-SU-2022:3408-1
SUSE-SU-2022:3422-1
SUSE-SU-2022:3450-1
SUSE-SU-2022:3609-1
SUSE-SU-2022:3809-1
SUSE-SU-2022:4617-1
SUSE-SU-2023:0416-1
USN-5650-1
USN-5693-1
USN-5727-1
USN-5727-2
USN-5728-1
USN-5728-2
USN-5728-3
USN-5729-1
USN-5729-2
USN-5774-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Linux Kernel
Red Hat
Suse
Ubuntu