CVE-2022-0998: Integer Overflow
An integer overflow flaw was found in the Linux kernel’s virtio device driver code in the way a user triggers the vhostvdpaconfigvalidate function. This flaw allows a local user to crash or potentially escalate their privileges on the system.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-0998?
CVE-2022-0998 is an integer overflow flaw in the Linux kernel's virtio device driver code that allows a local user to crash or potentially escalate their privileges.
How does CVE-2022-0998 affect Linux?
CVE-2022-0998 affects Linux kernel versions from 5.7 to 5.10.88 and versions from 5.11 to 5.15.11.
How severe is CVE-2022-0998?
CVE-2022-0998 has a severity rating of 7.8 (high).
How can I fix CVE-2022-0998?
To fix CVE-2022-0998, you should update your Linux kernel to a version that is not vulnerable.
Where can I find more information about CVE-2022-0998?
You can find more information about CVE-2022-0998 in the references provided: http://www.openwall.com/lists/oss-security/2022/04/02/1, https://lore.kernel.org/netdev/20220123001216.2460383-13-sashal@kernel.org/, https://security.netapp.com/advisory/ntap-20220513-0003/