Vulnerabilities > CVE-2022-0322 - Incorrect Type Conversion or Cast vulnerability in multiple products

047910
CVSS 5.5 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH

Summary

A flaw was found in the sctp_make_strreset_req function in net/sctp/sm_make_chunk.c in the SCTP network protocol in the Linux kernel with a local user privilege access. In this flaw, an attempt to use more buffer than is allocated triggers a BUG_ON issue, leading to a denial of service (DOS).

Vulnerable Configurations

Part Description Count
OS
Linux
4447
OS
Fedoraproject
1
Application
Oracle
3

Common Weakness Enumeration (CWE)