ZeroHour

CVE-2022-0500

CVSS 3.1
7.8 high
EPSS
<1%p29
Published
()
Modified
Description

A flaw was found in unrestricted eBPF usage by the BPF_BTF_LOAD, leading to a possible out-of-bounds memory write in the Linux kernel’s BPF subsystem due to the way a user loads BTF. This flaw allows a local user to crash or escalate their privileges on the system.

Vendors
linuxfedoraprojectnetapp
Products
linux kernel, fedora, h300e firmware, h300s firmware, h410c firmware, h410s firmware, h500e firmware, h500s firmware, h700e firmware, h700s firmware
Weakness
CWE-119, CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.