CVE-2022-3435: Linux Kernel IPv4 fib_semantics.c fib_nh_match out-of-bounds
A vulnerability classified as problematic has been found in Linux Kernel. This affects the function fibnhmatch of the file net/ipv4/fibsemantics.c of the component IPv4 Handler. The manipulation leads to out-of-bounds read. It is possible to initiate the attack remotely. It is recommended to apply a patch to fix this issue. The identifier VDB-210357 was assigned to this vulnerability.
Other sources
An out-of-bounds memory read flaw was found in the Linux kernel. The IPv4 Handler component may delete IPv4 routes containing a multipath spec while the fibinfo is using a nexthop object. This issue allows a local attacker access to unauthorized data.
This affects the function fibnhmatch of the file net/ipv4/fibsemantics.c of the component IPv4 Handler. The manipulation leads to out-of-bounds read. It is possible to initiate the attack remotely.
Reference:
https://vuldb.com/?id.210357 https://lore.kernel.org/netdev/20221005181257.8897-1-dsahern@kernel.org/T/#u
— Red Hat
Affected Software
Remediation
Information
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2022-3435?
CVE-2022-3435 is classified as a problematic vulnerability affecting the Linux Kernel.
How do I fix CVE-2022-3435?
To remediate CVE-2022-3435, update to the specified kernel versions for your distribution as mentioned in the advisory.
What component is affected by CVE-2022-3435?
CVE-2022-3435 affects the IPv4 Handler in the Linux Kernel.
Can CVE-2022-3435 be exploited remotely?
Yes, CVE-2022-3435 can be exploited remotely through out-of-bounds read manipulations.
Which distributions are impacted by CVE-2022-3435?
CVE-2022-3435 impacts various distributions including Red Hat, Fedora, and Debian.