CVE-2022-27666: Buffer Overflow
A heap buffer overflow flaw was found in IPsec ESP transformation code in net/ipv4/esp4.c and net/ipv6/esp6.c. This flaw allows a local attacker with a normal user privilege to overwrite kernel heap objects and may cause a local privilege escalation threat.
Affected Software
Remediation
Information
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2022-27666?
CVE-2022-27666 is classified as a critical vulnerability due to its potential for local privilege escalation.
How do I fix CVE-2022-27666?
To remediate CVE-2022-27666, upgrade to kernel version 0:4.18.0-372.13.1.rt7.170.el8_6 or later for affected Red Hat distributions.
Which software is affected by CVE-2022-27666?
CVE-2022-27666 affects specific kernels including versions of Red Hat kernel and kernel-rt prior to their patched releases.
What type of vulnerability is CVE-2022-27666?
CVE-2022-27666 is a heap buffer overflow vulnerability found in IPsec ESP transformation code.
Can CVE-2022-27666 be exploited remotely?
CVE-2022-27666 is a local privilege escalation vulnerability, meaning it requires local user access to exploit.