PT-2022-6186 · Linux+8 · Linux Kernel+8
Jialiang Wang
·
Published
2022-01-31
·
Updated
2024-02-20
·
CVE-2022-3545
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux Kernel (affected versions not specified)
Description
The issue is related to the use of memory after it has been freed, which can be exploited to execute arbitrary code. The vulnerability affects the
area cache get function in the drivers/net/ethernet/netronome/nfp/nfpcore/nfp cppcore.c file of the IPsec component. The manipulation leads to use after free.Recommendations
To fix this issue, it is recommended to apply a patch.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Buffer Overflow
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Almalinux
Astra Linux
Centos
Linux Kernel
Linuxmint
Red Hat
Suse
Ubuntu