CVE-2022-0435

CVSS v3.1 8.8 (High)
88% Progress
CVSS v2.0 9 (High)
90% Progress
EPSS 0.95 % (83th)
0.95% Progress
Affected Products 38
Advisories 43

A stack overflow flaw was found in the Linux kernel's TIPC protocol functionality in the way a user sends a packet with malicious content where the number of domain member nodes is higher than the 64 allowed. This flaw allows a remote user to crash the system or possibly escalate their privileges if they have access to the TIPC network.

Weaknesses
CWE-787
Out-of-bounds Write
Related CVEs
CVE Status
PUBLISHED
CNA
Red Hat, Inc.
Published Date
2022-03-25 19:15:10
(2 years ago)
Updated Date
2023-02-14 19:36:46
(19 months ago)

Affected Products

Loading...
Loading...

Configuration #1

AND
    CPE23 From Up To
OR  
  Linux Kernel from 4.8 version and prior 4.9.301 version cpe:2.3:o:linux:linux_kernel >= 4.8 < 4.9.301
OR  
  Running on/with
  Linux Kernel from 4.10 version and prior 4.14.266 version cpe:2.3:o:linux:linux_kernel >= 4.10 < 4.14.266
OR  
  Running on/with
  Linux Kernel from 4.15 version and prior 4.19.229 version cpe:2.3:o:linux:linux_kernel >= 4.15 < 4.19.229
OR  
  Running on/with
  Linux Kernel from 4.20 version and prior 5.4.179 version cpe:2.3:o:linux:linux_kernel >= 4.20 < 5.4.179
OR  
  Running on/with
  Linux Kernel from 5.5 version and prior 5.10.100 version cpe:2.3:o:linux:linux_kernel >= 5.5 < 5.10.100
OR  
  Running on/with
  Linux Kernel from 5.11 version and prior 5.15.23 version cpe:2.3:o:linux:linux_kernel >= 5.11 < 5.15.23
OR  
  Running on/with
  Linux Kernel from 5.16 version and prior 5.16.9 version cpe:2.3:o:linux:linux_kernel >= 5.16 < 5.16.9
OR  
  Running on/with
  Linux Kernel 5.17 cpe:2.3:o:linux:linux_kernel:5.17:-
OR  
  Running on/with
  Linux Kernel 5.17 Rc1 cpe:2.3:o:linux:linux_kernel:5.17:rc1
OR  
  Running on/with
  Linux Kernel 5.17 Rc2 cpe:2.3:o:linux:linux_kernel:5.17:rc2
OR  
  Running on/with
  Linux Kernel 5.17 Rc3 cpe:2.3:o:linux:linux_kernel:5.17:rc3

Configuration #2

AND
    CPE23 From Up To
OR  
  Redhat Codeready Linux Builder 8.0 cpe:2.3:a:redhat:codeready_linux_builder:8.0
OR  
  Running on/with
  Redhat Codeready Linux Builder 8.4 cpe:2.3:a:redhat:codeready_linux_builder:8.4
OR  
  Running on/with
  Redhat Codeready Linux Builder Eus 8.2 cpe:2.3:a:redhat:codeready_linux_builder_eus:8.2
OR  
  Running on/with
  Redhat Codeready Linux Builder Eus for Power Little Endian 8.2 cpe:2.3:a:redhat:codeready_linux_builder_eus_for_power_little_endian:8.2
OR  
  Running on/with
  Redhat Codeready Linux Builder for Power Little Endian Eus 8.0 cpe:2.3:a:redhat:codeready_linux_builder_for_power_little_endian_eus:8.0
OR  
  Running on/with
  Redhat Codeready Linux Builder for Power Little Endian Eus 8.4 cpe:2.3:a:redhat:codeready_linux_builder_for_power_little_endian_eus:8.4
OR  
  Running on/with
  Redhat Enterprise Linux 8.0 cpe:2.3:o:redhat:enterprise_linux:8.0
OR  
  Running on/with
  Redhat Enterprise Linux Eus 8.2 cpe:2.3:o:redhat:enterprise_linux_eus:8.2
OR  
  Running on/with
  Redhat Enterprise Linux Eus 8.4 cpe:2.3:o:redhat:enterprise_linux_eus:8.4
OR  
  Running on/with
  Redhat Enterprise Linux for Ibm Z Systems 8.0 cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:8.0
OR  
  Running on/with
  Redhat Enterprise Linux for Ibm Z Systems Eus 8.2 cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:8.2
OR  
  Running on/with
  Redhat Enterprise Linux for Ibm Z Systems Eus 8.4 cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:8.4
OR  
  Running on/with
  Redhat Enterprise Linux for Power Little Endian 8.0 cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian:8.0
OR  
  Running on/with
  Redhat Enterprise Linux for Power Little Endian Eus 8.2 cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:8.2
OR  
  Running on/with
  Redhat Enterprise Linux for Power Little Endian Eus 8.4 cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:8.4
OR  
  Running on/with
  Redhat Enterprise Linux for Real Time 8 cpe:2.3:o:redhat:enterprise_linux_for_real_time:8
OR  
  Running on/with
  Redhat Enterprise Linux for Real Time For Nfv 8 cpe:2.3:o:redhat:enterprise_linux_for_real_time_for_nfv:8
OR  
  Running on/with
  Redhat Enterprise Linux for Real Time For Nfv Tus 8.2 cpe:2.3:o:redhat:enterprise_linux_for_real_time_for_nfv_tus:8.2
OR  
  Running on/with
  Redhat Enterprise Linux for Real Time For Nfv Tus 8.4 cpe:2.3:o:redhat:enterprise_linux_for_real_time_for_nfv_tus:8.4
OR  
  Running on/with
  Redhat Enterprise Linux for Real Time Tus 8.2 cpe:2.3:o:redhat:enterprise_linux_for_real_time_tus:8.2
OR  
  Running on/with
  Redhat Enterprise Linux for Real Time Tus 8.4 cpe:2.3:o:redhat:enterprise_linux_for_real_time_tus:8.4
OR  
  Running on/with
  Redhat Enterprise Linux Server Aus 8.2 cpe:2.3:o:redhat:enterprise_linux_server_aus:8.2
OR  
  Running on/with
  Redhat Enterprise Linux Server Aus 8.4 cpe:2.3:o:redhat:enterprise_linux_server_aus:8.4
OR  
  Running on/with
  Redhat Enterprise Linux Server for Power Little Endian Update Services For Sap Solutions 8.2 cpe:2.3:o:redhat:enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions:8.2
OR  
  Running on/with
  Redhat Enterprise Linux Server for Power Little Endian Update Services For Sap Solutions 8.4 cpe:2.3:o:redhat:enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions:8.4
OR  
  Running on/with
  Redhat Enterprise Linux Server Tus 8.2 cpe:2.3:o:redhat:enterprise_linux_server_tus:8.2
OR  
  Running on/with
  Redhat Enterprise Linux Server Tus 8.4 cpe:2.3:o:redhat:enterprise_linux_server_tus:8.4
OR  
  Running on/with
  Redhat Enterprise Linux Server Update Services for Sap Solutions 8.2 cpe:2.3:o:redhat:enterprise_linux_server_update_services_for_sap_solutions:8.2
OR  
  Running on/with
  Redhat Enterprise Linux Server Update Services for Sap Solutions 8.4 cpe:2.3:o:redhat:enterprise_linux_server_update_services_for_sap_solutions:8.4

Configuration #3

AND
    CPE23 From Up To
OR  
  Redhat Virtualization 4.0 cpe:2.3:a:redhat:virtualization:4.0
OR  
  Running on/with
  Redhat Virtualization Host 4.0 cpe:2.3:a:redhat:virtualization_host:4.0
OR  
  Running on/with
  Redhat Enterprise Linux 8.0 cpe:2.3:o:redhat:enterprise_linux:8.0

Configuration #4

AND
    CPE23 From Up To
OR  
  Ovirt Node 4.4.10 cpe:2.3:o:ovirt:node:4.4.10

Configuration #5

AND
    CPE23 From Up To
OR  
  Fedoraproject Fedora 34 cpe:2.3:o:fedoraproject:fedora:34
OR  
  Running on/with
  Fedoraproject Fedora 35 cpe:2.3:o:fedoraproject:fedora:35

Configuration #6

AND
    CPE23 From Up To
OR  
  Netapp H300e Firmware cpe:2.3:o:netapp:h300e_firmware:-
OR  
  Running on/with
  Netapp H300e cpe:2.3:h:netapp:h300e:-

Configuration #7

AND
    CPE23 From Up To
OR  
  Netapp H300s Firmware cpe:2.3:o:netapp:h300s_firmware:-
OR  
  Running on/with
  Netapp H300s cpe:2.3:h:netapp:h300s:-

Configuration #8

AND
    CPE23 From Up To
OR  
  Netapp H410s Firmware cpe:2.3:o:netapp:h410s_firmware:-
OR  
  Running on/with
  Netapp H410s cpe:2.3:h:netapp:h410s:-

Configuration #9

AND
    CPE23 From Up To
OR  
  Netapp H500e Firmware cpe:2.3:o:netapp:h500e_firmware:-
OR  
  Running on/with
  Netapp H500e cpe:2.3:h:netapp:h500e:-

Configuration #10

AND
    CPE23 From Up To
OR  
  Netapp H500s Firmware cpe:2.3:o:netapp:h500s_firmware:-
OR  
  Running on/with
  Netapp H500s cpe:2.3:h:netapp:h500s:-

Configuration #11

AND
    CPE23 From Up To
OR  
  Netapp H700e Firmware cpe:2.3:o:netapp:h700e_firmware:-
OR  
  Running on/with
  Netapp H700e cpe:2.3:h:netapp:h700e:-

Configuration #12

AND
    CPE23 From Up To
OR  
  Netapp H700s Firmware cpe:2.3:o:netapp:h700s_firmware:-
OR  
  Running on/with
  Netapp H700s cpe:2.3:h:netapp:h700s:-
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...