CVE-2022-0382: Medium severity linux kernel vulnerability
An information leak flaw was found due to uninitialized memory in the Linux kernel's TIPC protocol subsystem, in the way a user sends a TIPC datagram to one or more destinations. This flaw allows a local user to read some kernel memory. This issue is limited to no more than 7 bytes, and the user cannot control what is read. This flaw affects the Linux kernel versions prior to 5.17-rc1.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-0382?
CVE-2022-0382 has been classified as a medium-severity vulnerability due to its potential to allow local users to read sensitive kernel memory.
How do I fix CVE-2022-0382?
To fix CVE-2022-0382, update your Linux kernel to a version that is patched, such as 5.10.223-1, 5.10.226-1, 6.1.119-1, 6.1.123-1, 6.12.11-1, or 6.12.12-1.
Who is affected by CVE-2022-0382?
CVE-2022-0382 affects local users with access to systems running vulnerable versions of the Linux kernel prior to 5.16.10.
What is the nature of the vulnerability in CVE-2022-0382?
CVE-2022-0382 is an information leak vulnerability caused by uninitialized memory in the TIPC protocol subsystem of the Linux kernel.
Can CVE-2022-0382 be exploited remotely?
No, CVE-2022-0382 cannot be exploited remotely as it requires local access to the system to read kernel memory.