CVE-2022-25636

Name
CVE-2022-25636
Description
net/netfilter/nf_dup_netdev.c in the Linux kernel 5.4 through 5.6.10 allows local users to gain privileges because of a heap out-of-bounds write. This is related to nf_tables_offload.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Patch https://git.kernel.org/pub/scm/linux/kernel/git/netfilter/nf.git/commit/?id=b1a5983f56e371046dcf164f90bfaf704d2b89f6
Exploit https://www.openwall.com/lists/oss-security/2022/02/21/2
Mailing List http://www.openwall.com/lists/oss-security/2022/02/22/1
DEBIAN https://www.debian.org/security/2022/dsa-5095
MISC https://nickgregory.me/linux/security/2022/03/12/cve-2022-25636/
MISC https://github.com/Bonfee/CVE-2022-25636
MISC http://packetstormsecurity.com/files/166444/Kernel-Live-Patch-Security-Notice-LSN-0085-1.html
CONFIRM https://security.netapp.com/advisory/ntap-20220325-0002/
N/A https://www.oracle.com/security-alerts/cpujul2022.html

Match rules

CPE URI Source package Min version Max version
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* linux_kernel >= 5.4 <= 5.6.10
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* linux_kernel >= 5.16 < 5.16.12
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* linux_kernel >= 5.11 < 5.15.26
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* linux_kernel >= 5.5 < 5.10.103
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* linux_kernel >= 5.4 < 5.4.182

Vulnerable and fixed packages

Source package Branch Version Maintainer Status