ID:9110 - Exploit for Improper Control of Dynamically-Managed Code Resources in Linux kernel - CVE-2022-25265

 
Main Vulnerability Database Exploits ID:9110 - Exploit for Improper Control of Dynamically-Managed Code Resources in Linux kernel - CVE-2022-25265

ID:9110 - Exploit for Improper Control of Dynamically-Managed Code Resources in Linux kernel - CVE-2022-25265

Published: June 14, 2023


Vulnerability identifier: #VU76191
Vulnerability risk: Low
CVE-ID: CVE-2022-25265
CWE-ID: CWE-913
Exploitation vector: Local access
Vulnerable software:
Linux kernel

Link to public exploit:


Vulnerability description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to an error in Linux kernel due to certain binary files may have the exec-all attribute if they were built in approximately 2003 (e.g., with GCC 3.2.2 and Linux kernel 2.4.20). This can cause execution of bytes located in supposedly non-executable regions of a file.


Remediation

Install updates from vendor's website.