Vulnerabilities > CVE-2022-0500 - Out-of-bounds Write vulnerability in multiple products

047910
CVSS 7.8 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH

Summary

A flaw was found in unrestricted eBPF usage by the BPF_BTF_LOAD, leading to a possible out-of-bounds memory write in the Linux kernel’s BPF subsystem due to the way a user loads BTF. This flaw allows a local user to crash or escalate their privileges on the system.

Vulnerable Configurations

Part Description Count
OS
Linux
419
OS
Fedoraproject
2
OS
Netapp
8
Hardware
Netapp
8

Common Weakness Enumeration (CWE)

References