Buffer overflow in Linux kernel - CVE-2022-2078

 

Buffer overflow in Linux kernel - CVE-2022-2078

Published: July 21, 2022 / Updated: August 7, 2023


Vulnerability identifier: #VU65642
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-2078
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a boundary error within the nft_set_desc_concat_parse() function in Linux kernel. A local user can trigger memory corruption and execute arbitrary code with elevated privileges.



Affected software

Linux kernel
Amazon Linux AMI
Anolis OS
Red Hat Enterprise Linux for Real Time
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Real Time for NFV
Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support
Oracle Linux
Slackware Linux
openEuler
Ubuntu
Red Hat OpenShift Container Platform
OpenShift Logging
IBM Spectrum Protect Plus
IBM Spectrum Copy Data Management
Red Hat Advanced Cluster Management for Kubernetes
kernel (Red Hat package)
kernel-rt (Red Hat package)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
bpftool
kernel-tools-devel
kernel-tools
kernel-devel
python3-perf-debuginfo
python2-perf
perf
python2-perf-debuginfo
python3-perf
kernel
perf-debuginfo
kernel-tools-debuginfo
kernel-debugsource
kernel-source
bpftool-debuginfo
kernel-debuginfo
kernel-debug
kernel-debug-modules
kernel-debug-devel
kernel-debug-core
kernel-debug-modules-extra
kernel-headers
kernel-modules
kernel-modules-extra
kernel-modules-internal
kernel-tools-libs
kernel-tools-libs-devel
kernel-core
linux-5.15.63/kernel-modules
linux-5.15.63/kernel-huge
linux-5.15.63/kernel-headers
linux-5.15.63/kernel-generic
linux-image-oem-22.04a (Ubuntu package)
linux-image-oem-22.04 (Ubuntu package)
linux-image-5.17.0-1013-oem (Ubuntu package)
XtremIO X2

How to mitigate CVE-2022-2078

Install updates from vendor's website.

Linux kernel - update to 5.19 rc1
Red Hat OpenShift Container Platform - update to 4.13.33
OpenShift Logging - addressed in versions 5.3.14, 5.5.5
kernel (Red Hat package) - addressed in versions 4.18.0-372.91.1.el8_6, 4.18.0-425.3.1.el8, 5.14.0-70.26.1.el9_0
kernel-rt (Red Hat package) - addressed in versions 4.18.0-425.3.1.rt7.213.el8, 5.14.0-70.26.1.rt21.98.el9_0
IBM Spectrum Protect Plus - update to 10.1.14
IBM Spectrum Copy Data Management - update to 2.2.18.1
Red Hat Advanced Cluster Management for Kubernetes - update to 2.6.3
bpftool - update to 4.19.90-2207.1.0.0157
kernel-tools-devel - update to 4.19.90-2207.1.0.0157
kernel-tools - update to 4.19.90-2207.1.0.0157
kernel-devel - update to 4.19.90-2207.1.0.0157
python3-perf-debuginfo - update to 4.19.90-2207.1.0.0157
python2-perf - update to 4.19.90-2207.1.0.0157
perf - update to 4.19.90-2207.1.0.0157
python2-perf-debuginfo - update to 4.19.90-2207.1.0.0157
python3-perf - update to 4.19.90-2207.1.0.0157
kernel - update to 4.19.90-2207.1.0.0157
perf-debuginfo - update to 4.19.90-2207.1.0.0157
kernel-tools-debuginfo - update to 4.19.90-2207.1.0.0157
kernel-debugsource - update to 4.19.90-2207.1.0.0157
kernel-source - update to 4.19.90-2207.1.0.0157
bpftool-debuginfo - update to 4.19.90-2207.1.0.0157
kernel-debuginfo - update to 4.19.90-2207.1.0.0157
kernel-debug - update to 5.10.134-12
kernel-debug-modules - update to 5.10.134-12
kernel-debug-devel - update to 5.10.134-12
kernel-debug-core - update to 5.10.134-12
python3-perf - update to 5.10.134-12
kernel-debug-modules-extra - update to 5.10.134-12
kernel-devel - update to 5.10.134-12
kernel-headers - update to 5.10.134-12
kernel-modules - update to 5.10.134-12
kernel-modules-extra - update to 5.10.134-12
kernel-modules-internal - update to 5.10.134-12
kernel-tools - update to 5.10.134-12
kernel-tools-libs - update to 5.10.134-12
kernel-tools-libs-devel - update to 5.10.134-12
perf - update to 5.10.134-12
kernel-core - update to 5.10.134-12
kernel - update to 5.10.134-12
bpftool - update to 5.10.134-12
linux-5.15.63/kernel-modules - update to 5.15.63
linux-5.15.63/kernel-huge - update to 5.15.63
linux-5.15.63/kernel-headers - update to 5.15.63
linux-5.15.63/kernel-generic - update to 5.15.63
linux-image-oem-22.04a (Ubuntu package) - update to 5.17.0.1013.12
linux-image-oem-22.04 (Ubuntu package) - update to 5.17.0.1013.12
linux-image-5.17.0-1013-oem (Ubuntu package) - update to 5.17.0-1013.14
kernel - update to 6.1.10-15.42
XtremIO X2 - update to 6.4.1-11

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins