PT-2021-6126 · Linux+6 · Linux Kernel+6

Published

2021-05-19

·

Updated

2026-03-14

·

CVE-2022-25265

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions through 5.16.10
Description The issue is related to a buffer overflow in the Linux kernel, which can be exploited by a remote attacker to execute arbitrary code. Certain binary files built around 2003, for example with GCC 3.2.2 and Linux kernel 2.4.20, may have the exec-all attribute, causing execution of bytes in supposedly non-executable regions of a file.
Recommendations For Linux kernel versions through 5.16.10, update to a version later than 5.16.10 to resolve the issue. As a temporary workaround, consider restricting access to potentially vulnerable binary files built with older versions of GCC and the Linux kernel.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2023:2736
ALSA-2023:2951
ALT-PU-2022-1387
ALT-PU-2022-1456
ALT-PU-2022-1647
ALT-PU-2022-2155
ALT-PU-2023-1684
ALT-PU-2023-1741
ALT-PU-2023-1814
ALT-PU-2023-4894
AZL-8641
BDU:2022-00899
CESA-2023_2736
CESA-2023_2951
CVE-2022-25265
ECHO-68C9-0000-6F1F
RHSA-2023:2736
RHSA-2023:2951
RHSA-2023_2736
RHSA-2023_2951
RHSA-2024:0724

Affected Products

Alt Linux
Almalinux
Centos
Debian
Gcc
Linux Kernel
Red Hat