Wind River Support Network

HomeDefectsLINCD-9733
Fixed

LINCD-9733 : Security Advisory - linux - CVE-2022-34918

Created: Jul 4, 2022    Updated: Aug 17, 2022
Resolved Date: Jul 26, 2022
Found In Version: 10.20.6.0
Fix Version: 10.22.33.0
Severity: Standard
Applicable for: Wind River Linux CD
Component/s: Kernel

Description

An issue was discovered in the Linux kernel through 5.18.9. A type confusion bug in nft_set_elem_init (leading to a buffer overflow) could be used by a local attacker to escalate privileges, a different vulnerability than CVE-2022-32250. (The attacker can obtain root access, but must start with an unprivileged user namespace to obtain CAP_NET_ADMIN access.) This can be fixed in nft_setelem_parse_data in net/netfilter/nf_tables_api.c.

CREATE(Triage):(User=admin) CVE-2022-34918 (https://nvd.nist.gov/vuln/detail/CVE-2022-34918)

CVEs


Live chat
Online