CVE-2022-25636: High severity Linux Linux kernel vulnerability
An out-of-bounds (OOB) memory access flaw was found in nftfwddupnetdevoffload in net/netfilter/nfdupnetdev.c in netfilter subcomponent in the Linux kernel due to a heap out of bounds write problem. In this flaw, an attacker with a user account on the system to gain access to out-of-bounds memory leads to a system crash or a privilege escalation threat.
Reference:
https://git.kernel.org/pub/scm/linux/kernel/git/netfilter/nf.git/commit/?id=b1a5983f56e371046dcf164f90bfaf704d2b89f6 https://www.openwall.com/lists/oss-security/2022/02/21/2
Other sources
An out-of-bounds (OOB) memory access flaw was found in nftfwddupnetdevoffload in net/netfilter/nfdupnetdev.c in the netfilter subcomponent in the Linux kernel due to a heap out-of-bounds write problem. This flaw allows a local attacker with a user account on the system to gain access to out-of-bounds memory, leading to a system crash or a privilege escalation threat.
net/netfilter/nfdupnetdev.c in the Linux kernel 5.4 through 5.6.10 allows local users to gain privileges because of a heap out-of-bounds write. This is related to nftablesoffload.
Affected Software
Remediation
Information
Patch Available
Patch Available
Mitigation
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2022-25636?
CVE-2022-25636 has been classified as a high severity vulnerability due to the potential for out-of-bounds memory access and exploitation.
How do I fix CVE-2022-25636?
To fix CVE-2022-25636, users should update their kernel to the patched versions provided by their respective distributions, such as kernel-rt or the standard kernel from Red Hat and Debian.
What types of systems are affected by CVE-2022-25636?
CVE-2022-25636 affects Linux kernel versions that are susceptible to the identified out-of-bounds memory access issue, particularly those versions between 5.4 and 5.16.
Can CVE-2022-25636 be exploited remotely?
CVE-2022-25636 requires an attacker to have local user access to exploit the vulnerability, thus making remote exploitation less likely.
What can attackers achieve by exploiting CVE-2022-25636?
Exploiting CVE-2022-25636 may allow attackers to corrupt memory, leading to potential denial of service or gaining control over the affected systems.