Wind River Support Network

HomeDefectsLIN1021-2889
Acknowledged

LIN1021-2889 : Security Advisory - linux - CVE-2022-0500

Created: Feb 21, 2022    Updated: Mar 26, 2022
Found In Version: 10.21.20.1
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Kernel

Description

A flaw was found in unrestricted eBPF usage by the BPF_BTF_LOAD, leading to a possible out-of-bounds memory write in the Linux kernel’s BPF subsystem due to the way a user loads BTF. This flaw allows a local user to crash or escalate their privileges on the system.

https://nvd.nist.gov/vuln/detail/CVE-2022-0500
Live chat
Online