CVE-2022-0264: Medium severity Linux Linux kernel vulnerability

Published Jan 17, 2022
·
Updated

A flaw was found in the Linux kernel. There is an address leakage in BPF atomic fetch. This allows a local user with the ability to insert EBPF rules to be able to gather additional information for further attacks on the kernel.

Reference and upstream patch: https://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf.git/commit/?id=7d3baf0afa3aa9102d6a521a8e4c41888bb79882

Other sources

A vulnerability was found in the Linux kernel's eBPF verifier when handling internal data structures. Internal memory locations could be returned to userspace. A local attacker with the permissions to insert eBPF code to the kernel can use this to leak internal kernel memory details defeating some of the exploit mitigations in place for the kernel. This flaws affects kernel versions < v5.16-rc6

Launchpad

Affected Software

9 affected componentsFixes available
redhat/kernel<5.16
5.16
Linux Linux kernel<5.16
Linux Linux kernel=5.16
Linux Linux kernel=5.16-rc1
Linux Linux kernel=5.16-rc2
Linux Linux kernel=5.16-rc3
Linux Linux kernel=5.16-rc4
Linux Linux kernel=5.16-rc5
debian/linux
5.10.223-15.10.234-16.1.129-16.1.135-16.12.25-16.12.27-1

Event History

Jan 17, 2022
Data Sourced
via Red Hat·04:51 PM
DescriptionSeverityAffected Software
Feb 4, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Jan 12, 2024
Data Sourced
via Launchpad·12:02 AM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·02:37 AM
RemedyDescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2022-0264?

CVE-2022-0264 is considered a medium severity vulnerability due to potential information leakage.

2

How do I fix CVE-2022-0264?

To fix CVE-2022-0264, upgrade to the latest kernel version beyond 5.16 or apply the available patches from your distribution.

3

Who is affected by CVE-2022-0264?

CVE-2022-0264 affects local users with the ability to insert eBPF rules on Linux kernel versions up to 5.16.

4

What impact can CVE-2022-0264 have?

CVE-2022-0264 allows a local user to leak memory addresses, which could lead to further attacks on the kernel.

5

Is CVE-2022-0264 exploitable remotely?

CVE-2022-0264 is not exploitable remotely as it requires local access to exploit the vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203