CVE-2022-0322: Incorrect Type Cast
A flaw was found in sctpmakestrresetreq in net/sctp/smmakechunk.c in SCTP network protocol in the Linux kernel. In this flaw, an attempt to use more buffer than was allocated triggers BUGON to cause a denial of service (DOS).
References: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=a2d859e3fc97e79d907761550dbc03ff1b36479c
Other sources
A flaw was found in the sctpmakestrresetreq function in net/sctp/smmakechunk.c in the SCTP network protocol in the Linux kernel with a local user privilege access. In this flaw, an attempt to use more buffer than is allocated triggers a BUGON issue, leading to a denial of service (DOS).
Affected Software
Remediation
Patch Available
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2022-0322?
CVE-2022-0322 is a vulnerability in the SCTP network protocol in the Linux kernel that can be exploited by a local user to cause a denial of service (DOS) attack.
What is the severity of CVE-2022-0322?
The severity of CVE-2022-0322 is medium, with a CVSS score of 5.5.
Which software is affected by CVE-2022-0322?
The Linux kernel versions up to 5.15, Fedora 35, Oracle Communications Cloud Native Core Binding Support Function 22.1.3, Oracle Communications Cloud Native Core Network Exposure Function 22.1.1, and Oracle Communications Cloud Native Core Policy 22.2.0 are affected by CVE-2022-0322.
How can CVE-2022-0322 be exploited?
CVE-2022-0322 can be exploited by a local user with privilege access to trigger a BUG_ON issue by attempting to use more buffer than is allocated, leading to a denial of service (DOS).
Where can I find more information about CVE-2022-0322?
You can find more information about CVE-2022-0322 in the following references: [1] [2] [3].