ZeroHour

CVE-2022-27666

CVSS 3.1
7.8 high
EPSS
6%p92
Published
()
Modified
Description

A heap buffer overflow flaw was found in IPsec ESP transformation code in net/ipv4/esp4.c and net/ipv6/esp6.c. This flaw allows a local attacker with a normal user privilege to overwrite kernel heap objects and may cause a local privilege escalation threat.

Vendors
linuxfedoraprojectredhatnetappdebian
Products
linux kernel, fedora, virtualization, enterprise linux, h300s firmware, h500s firmware, h700s firmware, h300e firmware, h500e firmware, h700e firmware, h410s firmware, h410c firmware
Weakness
CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news