PT-2022-7361 · Linux+1 · Linux Kernel+1

Ariel Miculas

·

Published

2022-06-09

·

Updated

2023-08-14

·

CVE-2022-32981

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.18.4
Description An issue was discovered in the Linux kernel on powerpc 32-bit platforms, where there is a buffer overflow in ptrace PEEKUSER and POKEUSER when accessing floating point registers. This issue is related to the ptrace get fpr() function in the arch/powerpc/kernel/ptrace/ptrace-fpu.c module of the ptrace component of the Linux kernel. The exploitation of this issue allows an attacker to impact the confidentiality, integrity, and availability of protected information or elevate their privileges.
Recommendations For Linux kernel versions prior to 5.18.4, update to version 5.18.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the ptrace PEEKUSER and POKEUSER functions until a patch is available. Additionally, restricting access to the ptrace get fpr() function in the arch/powerpc/kernel/ptrace/ptrace-fpu.c module may help minimize the risk of exploitation.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-2050
ALT-PU-2022-2131
ALT-PU-2022-2152
ALT-PU-2022-2155
ALT-PU-2023-1684
ALT-PU-2023-1741
ALT-PU-2023-1814
ALT-PU-2023-4894
AZL-9930
BDU:2024-04162
CVE-2022-32981
OESA-2022-1725

Affected Products

Alt Linux
Linux Kernel