CVE-2022-25265: High severity linux kernel vulnerability
A vulnerability was found in the Linux kernel when certain binary files have the exec-all attribute with gcc. This issue can cause the execution of bytes located in the non-executable regions of a file.
Other sources
In the Linux kernel through 5.16.10, certain binary files may have the exec-all attribute if they were built in approximately 2003 (e.g., with GCC 3.2.2 and Linux kernel 2.4.20). This can cause execution of bytes located in supposedly non-executable regions of a file.
Affected Software
Remediation
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2022-25265?
CVE-2022-25265 is a vulnerability found in the Linux kernel where certain binary files may have the exec-all attribute if they were built in approximately 2003, causing execution of bytes in non-executable regions of a file.
What is the severity of CVE-2022-25265?
The severity of CVE-2022-25265 is high.
How does CVE-2022-25265 affect Linux kernel versions?
CVE-2022-25265 affects Linux kernel versions up to and including 5.16.10.
Is the Netapp Baseboard Management Controller H300s vulnerable to CVE-2022-25265?
No, the Netapp Baseboard Management Controller H300s is not vulnerable to CVE-2022-25265.
How can I fix CVE-2022-25265?
To fix CVE-2022-25265, update your Linux kernel to a version above 5.16.10.