CVE-2022-36123: High severity linux kernel vulnerability
Published Jul 29, 2022
·Updated
The Linux kernel before 5.18.13 lacks a certain clear operation for the block starting symbol (.bss). This allows Xen PV guest OS users to cause a denial of service or gain privileges.
Affected Software
11 affected components
Linux Linux kernel<5.18.13
NetApp H300s Firmware
NetApp H300s
NetApp H500s Firmware
NetApp H500s
NetApp H700s Firmware
NetApp H700s
NetApp H410s Firmware
NetApp H410s
NetApp H410c Firmware
NetApp H410c
Remediation
Patch Available
Event History
Jul 29, 2022
CVE Published
via MITRE·01:43 PM
Data Sourced
via MITRE·01:43 PM
Description
Frequently Asked Questions
1
What is CVE-2022-36123?
CVE-2022-36123 is a vulnerability in the Linux kernel before version 5.18.13 that allows Xen PV guest OS users to cause a denial of service or gain privileges.
2
What is the severity of CVE-2022-36123?
The severity of CVE-2022-36123 is high, with a CVSS score of 7.8.
3
Which software versions are affected by CVE-2022-36123?
Linux kernel versions up to 5.18.13 are affected by CVE-2022-36123.
4
How can CVE-2022-36123 be exploited?
CVE-2022-36123 can be exploited by Xen PV guest OS users to cause a denial of service or gain privileges.
5
Is there a fix available for CVE-2022-36123?
Yes, a fix is available for CVE-2022-36123 in Linux kernel version 5.18.13.