PT-2022-6763 · Linux+5 · Linux Kernel+5

Duoming Zhou

·

Published

2022-08-08

·

Updated

2023-08-14

·

CVE-2022-3635

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux Kernel (affected versions not specified)
Description A critical issue has been found in the Linux Kernel, affecting the function tst timer of the file drivers/atm/idt77252.c of the component IPsec. The manipulation leads to use after free, which can be exploited due to a race condition. This may allow an attacker to impact the confidentiality, integrity, and availability of protected information.
Recommendations To fix this issue, it is recommended to apply a patch. As a temporary workaround, consider disabling the tst timer function until a patch is available. Restrict access to the vulnerable module drivers/atm/idt77252.c to minimize the risk of exploitation.

Exploit

Fix

Use After Free

Race Condition

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-2497
ALT-PU-2022-2509
ALT-PU-2022-2523
ALT-PU-2022-2529
ALT-PU-2022-2531
ALT-PU-2022-2532
ALT-PU-2022-2560
ALT-PU-2022-2633
ALT-PU-2022-2635
ALT-PU-2022-2664
ALT-PU-2022-2676
ALT-PU-2022-2682
ALT-PU-2022-2692
ALT-PU-2022-2915
ALT-PU-2022-2919
ALT-PU-2023-4894
BDU:2023-04272
CVE-2022-3635
DLA-3173-1
OESA-2022-2035
OESA-2022-2036
OESA-2022-2045
OPENSUSE-SU-2022_4503-1
OPENSUSE-SU-2022_4504-1
OPENSUSE-SU-2022_4574-1
OPENSUSE-SU-2022_4585-1
OPENSUSE-SU-2022_4613-1
OPENSUSE-SU-2022_4616-1
OPENSUSE-SU-2022_4617-1
SUSE-SU-2022:4503-1
SUSE-SU-2022:4504-1
SUSE-SU-2022:4505-1
SUSE-SU-2022:4561-1
SUSE-SU-2022:4566-1
SUSE-SU-2022:4573-1
SUSE-SU-2022:4574-1
SUSE-SU-2022:4585-1
SUSE-SU-2022:4589-1
SUSE-SU-2022:4611-1
SUSE-SU-2022:4613-1
SUSE-SU-2022:4614-1
SUSE-SU-2022:4615-1
SUSE-SU-2022:4616-1
SUSE-SU-2022:4617-1
SUSE-SU-2023:0416-1
USN-5727-1
USN-5727-2
USN-5728-1
USN-5728-2
USN-5728-3
USN-5729-1
USN-5729-2
USN-5758-1
USN-5774-1
USN-6247-1

Affected Products

Alt Linux
Astra Linux
Linux Kernel
Linuxmint
Suse
Ubuntu