Buffer overflow in Oracle Linux - CVE-2022-21546

 

Buffer overflow in Oracle Linux - CVE-2022-21546

Published: October 20, 2022


Vulnerability identifier: #VU68553
CSH Severity: Medium
CVSS v4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-21546
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error within the scsi subsystem within the OS kernel. A remote attacker can create a specially crafted file, trick the victim into opening it, trigger memory corruption and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

Oracle Linux
openEuler
Ubuntu
bpftool
kernel
python3-perf-debuginfo
python3-perf
python2-perf-debuginfo
python2-perf
perf-debuginfo
perf
kernel-tools-devel
kernel-tools
kernel-source
kernel-devel
kernel-debugsource
kernel-debuginfo
bpftool-debuginfo
kernel-tools-debuginfo
kernel-headers
linux-aws-fips (Ubuntu package)
linux (Ubuntu package)
linux-xilinx-zynqmp (Ubuntu package)
linux-intel-iot-realtime (Ubuntu package)
linux-raspi (Ubuntu package)
linux-intel-iotg-5.15 (Ubuntu package)
linux-kvm (Ubuntu package)
linux-azure-fips (Ubuntu package)
linux-azure (Ubuntu package)
linux-azure-5.15 (Ubuntu package)

How to mitigate CVE-2022-21546

Install updates from vendor's website.

bpftool - addressed in versions 4.19.90-2506.2.0.0331, 5.10.0-268.0.0.171
kernel - addressed in versions 4.19.90-2506.2.0.0331, 5.10.0-268.0.0.170, 5.10.0-268.0.0.171
python3-perf-debuginfo - addressed in versions 4.19.90-2506.2.0.0331, 5.10.0-268.0.0.170, 5.10.0-268.0.0.171
python3-perf - addressed in versions 4.19.90-2506.2.0.0331, 5.10.0-268.0.0.170, 5.10.0-268.0.0.171
python2-perf-debuginfo - update to 4.19.90-2506.2.0.0331
python2-perf - update to 4.19.90-2506.2.0.0331
perf-debuginfo - addressed in versions 4.19.90-2506.2.0.0331, 5.10.0-268.0.0.170, 5.10.0-268.0.0.171
perf - addressed in versions 4.19.90-2506.2.0.0331, 5.10.0-268.0.0.170, 5.10.0-268.0.0.171
kernel-tools-devel - addressed in versions 4.19.90-2506.2.0.0331, 5.10.0-268.0.0.170, 5.10.0-268.0.0.171
kernel-tools - addressed in versions 4.19.90-2506.2.0.0331, 5.10.0-268.0.0.170, 5.10.0-268.0.0.171
kernel-source - addressed in versions 4.19.90-2506.2.0.0331, 5.10.0-268.0.0.170, 5.10.0-268.0.0.171
kernel-devel - addressed in versions 4.19.90-2506.2.0.0331, 5.10.0-268.0.0.170, 5.10.0-268.0.0.171
kernel-debugsource - addressed in versions 4.19.90-2506.2.0.0331, 5.10.0-268.0.0.170, 5.10.0-268.0.0.171
kernel-debuginfo - addressed in versions 4.19.90-2506.2.0.0331, 5.10.0-268.0.0.170, 5.10.0-268.0.0.171
bpftool-debuginfo - addressed in versions 4.19.90-2506.2.0.0331, 5.10.0-268.0.0.171
kernel-tools-debuginfo - addressed in versions 4.19.90-2506.2.0.0331, 5.10.0-268.0.0.170, 5.10.0-268.0.0.171
kernel-headers - addressed in versions 5.10.0-268.0.0.170, 5.10.0-268.0.0.171
linux-aws-fips (Ubuntu package) - addressed in versions 5.15.0.144.84, 5.15.0-144.157+fips1, 5.15.0.1087.77, 5.15.0-1087.96+fips1, 5.15.0.1088.84, 5.15.0-1088.95+fips1
linux (Ubuntu package) - addressed in versions 5.15.0.144.130, 5.15.0.144.141, 5.15.0-144.157, 5.15.0-144.157~20.04.1, 5.15.0.144.157~20.04.1, 5.15.0-1030.30, 5.15.0.1030.32, 5.15.0.1041.41, 5.15.0-1041.41, 5.15.0.1041.41~20.04.1, 5.15.0-1041.41~20.04.1, 5.15.0.1070.69, 5.15.0-1070.78, 5.15.0.1080.76, 5.15.0-1080.83, 5.15.0-1080.83~20.04.1, 5.15.0.1080.83~20.04.1, 5.15.0.1082.82, 5.15.0-1082.83, 5.15.0.1083.83, 5.15.0-1083.89, 5.15.0.1085.81, 5.15.0.1085.84, 5.15.0-1085.91, 5.15.0-1085.91~20.04.3, 5.15.0.1085.91~20.04.3, 5.15.0.1087.83, 5.15.0-1087.96, 5.15.0.1087.96~20.04.1, 5.15.0-1087.96~20.04.2, 5.15.0.1088.91, 5.15.0-1088.95, 5.15.0.1088.95~20.04.1, 5.15.0-1088.95~20.04.1
linux-xilinx-zynqmp (Ubuntu package) - addressed in versions 5.15.0.1052.55, 5.15.0-1052.56
linux-intel-iot-realtime (Ubuntu package) - addressed in versions 5.15.0-1081.83, 5.15.0.1081.85, 5.15.0.1088.92, 5.15.0-1088.97
linux-raspi (Ubuntu package) - addressed in versions 5.15.0.1083.81, 5.15.0-1083.86
linux-intel-iotg-5.15 (Ubuntu package) - addressed in versions 5.15.0.1083.89~20.04.1, 5.15.0-1083.89~20.04.1
linux-kvm (Ubuntu package) - addressed in versions 5.15.0.1084.80, 5.15.0-1084.89
linux-azure-fips (Ubuntu package) - addressed in versions 5.15.0.1094.79, 5.15.0-1094.103+fips1
linux-azure (Ubuntu package) - addressed in versions 5.15.0.1094.92, 5.15.0-1094.103
linux-azure-5.15 (Ubuntu package) - addressed in versions 5.15.0-1094.103~20.04.1, 5.15.0.1094.103~20.04.1

External References

Related Security Bulletins