PT-2022-4764 · Linux+8 · Linux Kernel+8

Hangyu Hua

+1

·

Published

2022-06-02

·

Updated

2025-05-05

·

CVE-2022-36879

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions through 5.18.14
Description An issue was discovered in the Linux kernel where the xfrm expand policies function in net/xfrm/xfrm policy.c can cause a refcount to be dropped twice, potentially leading to a denial of service. This issue can be exploited by a remote attacker.
Recommendations For Linux kernel versions through 5.18.14, as a temporary workaround, consider disabling the xfrm expand policies function until a patch is available. Restrict access to the net/xfrm/xfrm policy.c module to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Resource Release

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-2319
ALT-PU-2022-2339
ALT-PU-2022-2915
ALT-PU-2022-2919
ALT-PU-2023-1684
ALT-PU-2023-1741
ALT-PU-2023-1814
ALT-PU-2023-4894
AZL-10401
BDU:2022-05664
CESA-2023_2736
CESA-2023_2951
CVE-2022-36879
DLA-3102-1
DLA-3131-1
DSA-5207-1
MGASA-2022-0278
MGASA-2022-0279
OESA-2022-1842
OPENSUSE-SU-2022_3264-1
OPENSUSE-SU-2022_3288-1
OPENSUSE-SU-2022_3293-1
OPENSUSE-SU-2022_3408-1
OPENSUSE-SU-2022_3609-1
OPENSUSE-SU-2022_4617-1
RHSA-2023:2148
RHSA-2023:2458
RHSA-2023:2736
RHSA-2023:2951
RHSA-2023:5627
RHSA-2023_2148
RHSA-2023_2458
RHSA-2023_2736
RHSA-2023_2951
RHSA-2024:0431
RHSA-2024:0432
SUSE-SU-2022:3263-1
SUSE-SU-2022:3264-1
SUSE-SU-2022:3265-1
SUSE-SU-2022:3274-1
SUSE-SU-2022:3282-1
SUSE-SU-2022:3288-1
SUSE-SU-2022:3291-1
SUSE-SU-2022:3293-1
SUSE-SU-2022:3294-1
SUSE-SU-2022:3408-1
SUSE-SU-2022:3422-1
SUSE-SU-2022:3450-1
SUSE-SU-2022:3609-1
SUSE-SU-2022:3809-1
SUSE-SU-2022:4617-1
SUSE-SU-2023:0416-1
USN-5667-1
USN-5668-1
USN-5677-1
USN-5682-1
USN-5683-1
USN-5703-1
USN-5706-1
USN-5727-1
USN-5727-2
USN-5774-1
USN-5913-1
USN-6001-1
USN-6013-1
USN-6014-1

Affected Products

Alt Linux
Astra Linux
Centos
Linuxmint
Linux Kernel
Red Hat
Red Os
Suse
Ubuntu