Linux Kernel eBPF local privilege escalation (CVE-2022-23222) vulnerability

Description:
kernel/bpf/verifier.c in the Linux kernel through 5.15.14 allows local users to gain privileges because of the availability of pointer arithmetic via certain *_OR_NULL pointer types. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

Impact: A local attacker may exploit this issue to gain elevated root privileges on the affected system.

Mitigation: Updates are available. Please check specific vendor advisory for more information.

Reference urls:

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23222
https://nvd.nist.gov/vuln/detail/CVE-2022-23222
https://ubuntu.com/security/CVE-2022-23222
https://access.redhat.com/security/cve/cve-2022-23222

Share