PT-2021-7740 · Linux+4 · Linux Kernel+4

Lucas Leong

+1

·

Published

2021-08-14

·

Updated

2025-03-11

·

CVE-2022-2991

CVSS v3.1

6.7

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux Kernel (affected versions not specified)
Description A heap-based buffer overflow was found in the Linux kernel's LightNVM subsystem due to the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. This issue allows a local attacker to escalate privileges and execute arbitrary code in the context of the kernel. The attacker must first obtain the ability to execute high-privileged code on the target system to exploit this issue.
Recommendations At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Heap Based Buffer Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-3330
ALT-PU-2021-3358
ALT-PU-2021-3563
ALT-PU-2021-3573
ALT-PU-2021-3660
ALT-PU-2022-1240
ALT-PU-2022-1419
ALT-PU-2022-1421
ALT-PU-2023-1814
ALT-PU-2023-4894
BDU:2023-02304
CVE-2022-2991
OESA-2022-1925
OESA-2022-1926
OESA-2022-1942
SUSE-SU-2022:3263-1
SUSE-SU-2022:3294-1
SUSE-SU-2023:0634-1
SUSE-SU-2023:0768-1
SUSE-SU-2023:0852-1
SUSE-SU-2023:1971-1
SUSE-SU-2023:1973-1
SUSE-SU-2023:1983-1
SUSE-SU-2023:2007-1
SUSE-SU-2023:2023-1
SUSE-SU-2025:0834-1
SUSE-SU-2025_0834-1
USN-6001-1
USN-6013-1
USN-6014-1
ZDI-22-960

Affected Products

Alt Linux
Astra Linux
Linux Kernel
Suse
Ubuntu