CVE-2022-30594: High severity Linux Linux kernel vulnerability
A flaw was found in the Linux kernel. The PTRACESEIZE code path allows attackers to bypass intended restrictions on setting the PTSUSPENDSECCOMP flag, possibly disabling seccomp.
Other sources
The Linux kernel before 5.17.2 mishandles seccomp permissions. The PTRACESEIZE code path allows attackers to bypass intended restrictions on setting the PTSUSPENDSECCOMP flag.
Affected Software
Remediation
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2022-30594?
CVE-2022-30594 has a high severity rating as it allows attackers to bypass seccomp restrictions.
How do I fix CVE-2022-30594?
To fix CVE-2022-30594, update the Linux kernel to the latest patched version as specified in the security advisories.
Which versions of the Linux kernel are affected by CVE-2022-30594?
CVE-2022-30594 affects Linux kernel versions prior to 5.17.2 and certain versions within the 4.x and 5.x series.
What components are impacted by CVE-2022-30594?
CVE-2022-30594 impacts the Linux kernel, specifically within the PTRACE_SEIZE code path related to seccomp.
Is CVE-2022-30594 exploitable remotely?
CVE-2022-30594 is not remote; it requires local access to the system to exploit the vulnerability.