CVE-2022-1353: Infoleak
A vulnerability was found in pfkeyregister in net/key/afkey.c in the Linux kernel. In this flaw, a local unprivileged user may gain access to kernel memory, leading to a system crash or a leak of internal kernel information.
Reference: https://lore.kernel.org/all/20220321215240.490132-2-sashal@kernel.org/
Other sources
A vulnerability was found in the pfkeyregister function in net/key/afkey.c in the Linux kernel. This flaw allows a local, unprivileged user to gain access to kernel memory, leading to a system crash or a leak of internal kernel information.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernel-rtto a version that resolves this vulnerability.Fixed in 0:4.18.0-372.32.1.rt7.189.el8_6 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:4.18.0-372.32.1.el8_6 - Upgrade
Upgrade
redhat/kernel-rtto a version that resolves this vulnerability.Fixed in 0:4.18.0-193.90.1.rt13.140.el8_2 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:4.18.0-193.90.1.el8_2 - Upgrade
Upgrade
redhat/kernel-rtto a version that resolves this vulnerability.Fixed in 0:4.18.0-305.62.1.rt7.134.el8_4 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:4.18.0-305.62.1.el8_4 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:5.14.0-162.6.1.el9_1 - Upgrade
Upgrade
redhat/kernel-rtto a version that resolves this vulnerability.Fixed in 0:5.14.0-162.6.1.rt21.168.el9_1 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 0:5.14.0-70.70.1.el9_0 - Upgrade
Upgrade
redhat/kernel-rtto a version that resolves this vulnerability.Fixed in 0:5.14.0-70.70.1.rt21.141.el9_0 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 5.17
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2022-1353?
CVE-2022-1353 has been categorized with a high severity rating due to its potential for kernel memory access and possible system crashes.
How do I fix CVE-2022-1353?
To mitigate CVE-2022-1353, ensure that your system is updated to the recommended kernel versions specified by Red Hat, such as 0:4.18.0-372.32.1.el8_6 or later.
Who is affected by CVE-2022-1353?
CVE-2022-1353 affects Linux kernel installations on systems utilizing kernel versions before the patched releases provided by Red Hat.
What type of vulnerability is CVE-2022-1353?
CVE-2022-1353 is a local privilege escalation vulnerability that allows an unprivileged user to access kernel memory.
Can CVE-2022-1353 be exploited remotely?
No, CVE-2022-1353 requires local access to the system, making it a local execution vulnerability.