PT-2022-1992 · Linux+10 · Linux Kernel+10

Valis

·

Published

2022-03-07

·

Updated

2025-09-29

·

CVE-2022-27666

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.16.15 Linux kernel versions prior to 5.17
Description A heap buffer overflow flaw was found in IPsec ESP transformation code in net/ipv4/esp4.c and net/ipv6/esp6.c. This flaw allows a local attacker with a normal user privilege to overwrite kernel heap objects and may cause a local privilege escalation threat. The vulnerability can be exploited by sending a large message, allowing the attacker to gain root privileges via modprobe path overwrite. Technical details about exploitation include page-level heap fengshui to gain page alloc-to-slab overflow, constructing arbitrary read/write using the msg msg kernel object.
Recommendations For Linux kernel versions prior to 5.16.15, update to version 5.16.15 or later to resolve the issue. For Linux kernel versions prior to 5.17, update to version 5.17 or later to resolve the issue. As a temporary workaround, consider disabling the vulnerable esp4 and esp6 modules until a patch is available. Restrict access to the vulnerable net/ipv4/esp4.c and net/ipv6/esp6.c files to minimize the risk of exploitation. Avoid using the msg msg kernel object in the affected API endpoints until the issue is resolved.

Exploit

Fix

DoS

LPE

Buffer Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2022:5249
ALSA-2022:5267
ALSA-2022:5316
ALSA-2022:5344
ALSA-2022_5316
ALSA-2022_5344
ALSA-2024_2394
ALSA-2025_16880
ALT-PU-2022-1647
ALT-PU-2022-1730
ALT-PU-2022-1768
ALT-PU-2022-1929
ALT-PU-2022-2155
ALT-PU-2023-1684
ALT-PU-2023-1741
ALT-PU-2023-1814
ALT-PU-2023-4894
AZL-13228
AZL-9120
BDU:2022-01567
CESA-2022_5219
CESA-2022_5316
CESA-2022_5344
CVE-2022-27666
DSA-5127-1
DSA-5173-1
ELSA-2022-5249
ELSA-2022-5316
ELSA-2022-9365
ELSA-2022-9366
ELSA-2022-9367
ELSA-2022-9368
MGASA-2022-0121
MGASA-2022-0122
OESA-2022-1621
OPENSUSE-SU-2022_1163-1
OPENSUSE-SU-2022_1183-1
RHSA-2022:4809
RHSA-2022:4829
RHSA-2022:4835
RHSA-2022:4924
RHSA-2022:4942
RHSA-2022:5214
RHSA-2022:5219
RHSA-2022:5220
RHSA-2022:5224
RHSA-2022:5249
RHSA-2022:5267
RHSA-2022:5316
RHSA-2022:5344
RHSA-2022:5476
RHSA-2022:5678
RHSA-2022_5249
RHSA-2022_5267
RHSA-2022_5316
RHSA-2022_5344
RLSA-2022:5316
RLSA-2022:5344
RLSA-2022_5316
RLSA-2022_5344
SUSE-SU-2022:1163-1
SUSE-SU-2022:1172-1
SUSE-SU-2022:1182-1
SUSE-SU-2022:1183-1
SUSE-SU-2022:1189-1
SUSE-SU-2022:1192-1
SUSE-SU-2022:1193-1
SUSE-SU-2022:1194-1
SUSE-SU-2022:1196-1
SUSE-SU-2022:1197-1
SUSE-SU-2022:1212-1
SUSE-SU-2022:1215-1
SUSE-SU-2022:1223-1
SUSE-SU-2022:1224-1
SUSE-SU-2022:1230-1
SUSE-SU-2022:1242-1
SUSE-SU-2022:1246-1
SUSE-SU-2022:1248-1
SUSE-SU-2022:1257-1
SUSE-SU-2022:1261-1
SUSE-SU-2022:1266-1
SUSE-SU-2022:1267-1
SUSE-SU-2022:1268-1
SUSE-SU-2022:1269-1
SUSE-SU-2022:1278-1
SUSE-SU-2022:1303-1
SUSE-SU-2022:1402-1
SUSE-SU-2022:1407-1
SUSE-SU-2022_1172-1
SUSE-SU-2022_1193-1
SUSE-SU-2022_1194-1
SUSE-SU-2022_1212-1
SUSE-SU-2022_1215-1
SUSE-SU-2022_1223-1
SUSE-SU-2022_1224-1
SUSE-SU-2022_1230-1
SUSE-SU-2022_1246-1
SUSE-SU-2022_1248-1
SUSE-SU-2022_1261-1
SUSE-SU-2022_1269-1
USN-5353-1
USN-5357-1
USN-5357-2
USN-5358-1
USN-5358-2
USN-5368-1
USN-5377-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Linux Kernel
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu