CVE-2022-0286: Null Pointer Dereference
A flaw was found in the Linux kernel. A null dereference in bondipsecaddsa() may lead to a local denial of service.
Upstream commit:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=105cd17a866017b45f3c45901b394c711c97bf40
References:
https://syzkaller.appspot.com/bug?id=160f641886d88bf11cbf1236cc4db994bb210626
Other sources
A flaw was found in the Linux kernel. A null pointer dereference in bondipsecaddsa() may lead to local denial of service.
A NULL pointer dereference flaw was found in the Linux kernel’s bonding driver in the way a user bonds non existing or fake device. This flaw allows a local user to crash the system, causing a denial of service.
Affected Software
Remediation
Patch Available
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2022-0286?
CVE-2022-0286 is a vulnerability in the Linux kernel that may lead to a denial of service attack due to a null pointer dereference in bond_ipsec_add_sa().
How does CVE-2022-0286 impact the system?
CVE-2022-0286 allows a local user to crash the system, resulting in a denial of service.
What is the severity of CVE-2022-0286?
The severity of CVE-2022-0286 is medium, with a severity value of 5.1.
Which software is affected by CVE-2022-0286?
Linux kernel versions up to and excluding 5.14, kernel-rt version 0:4.18.0-372.9.1.rt7.166.el8, and kernel version 0:4.18.0-372.9.1.el8 are affected by CVE-2022-0286.
How can I fix CVE-2022-0286?
To fix CVE-2022-0286, update to Linux kernel version 5.14 or later, kernel-rt version 0:4.18.0-372.9.1.rt7.166.el8 or later, or kernel version 0:4.18.0-372.9.1.el8 or later.