CVE-2022-0435: Critical severity Linux Linux kernel vulnerability
A remote stack overflow in the TIPC networking module. With FORTIFYSOURCE's stricter memcpy() bounds checking, this can be exploited to cause remote DOS via kernel panic on systems using TIPC. Prior to these bounds checks, and with a canary leak (or no CONFIGSTACKPROTECTOR), this can be exploited for RCE.
Reference: https://www.openwall.com/lists/oss-security/2022/02/10/1
Other sources
A stack overflow flaw was found in the Linux kernel's TIPC protocol functionality in the way a user sends a packet with malicious content where the number of domain member nodes is higher than the 64 allowed. This flaw allows a remote user to crash the system or possibly escalate their privileges if they have access to the TIPC network.
A stack overflow flaw was found in the Linux kernel’s TIPC protocol functionality in the way a user sends a packet with malicious content where the number of domain member nodes is higher than the 64 allowed. This flaw allows a remote user to crash the system or possibly escalate their privileges if they have access to the TIPC network.
Affected Software
Remediation
Information
Patch Available
Patch Available
Mitigation
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2022-0435?
CVE-2022-0435 is classified as a high severity vulnerability due to its potential for remote denial of service via kernel panic.
How do I fix CVE-2022-0435?
To mitigate CVE-2022-0435, upgrade your kernel to versions 0:4.18.0-348.20.1.rt7.150.el8_5 or 0:4.18.0-348.20.1.el8_5 for Red Hat systems.
Which systems are affected by CVE-2022-0435?
CVE-2022-0435 affects multiple versions of the Linux kernel, particularly those utilizing TIPC networking in Red Hat and Fedora distributions.
Can CVE-2022-0435 lead to system exploitation?
Exploitation of CVE-2022-0435 can result in a remote denial of service, which may crash systems utilizing the vulnerable TIPC module.
Is CVE-2022-0435 a local or remote vulnerability?
CVE-2022-0435 is a remote vulnerability, allowing attackers to potentially cause harm without requiring local access.