Wind River Support Network

HomeDefectsLINCD-8312
Fixed

LINCD-8312 : Security Advisory - linux - CVE-2022-0500

Created: Feb 21, 2022    Updated: Jun 15, 2022
Resolved Date: May 26, 2022
Found In Version: 10.20.6.0
Fix Version: 10.22.24.0
Severity: Standard
Applicable for: Wind River Linux CD
Component/s: Kernel

Description

A flaw was found in unrestricted eBPF usage by the BPF_BTF_LOAD, leading to a possible out-of-bounds memory write in the Linux kernel’s BPF subsystem due to the way a user loads BTF. This flaw allows a local user to crash or escalate their privileges on the system.

https://nvd.nist.gov/vuln/detail/CVE-2022-0500

CVEs


Live chat
Online