ZDI-26-193: (Pwn2Own) Linux Kernel nf_tables_newset Out-Of-Bounds Write Information Disclosure Vulnerability
This vulnerability allows local attackers to disclose sensitive information on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 3.8. The following CVEs are assigned: CVE-2022-1972.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-193?
ZDI-26-193 has a CVSS rating of 3.8, indicating a moderate level of severity.
How do I fix ZDI-26-193?
To mitigate ZDI-26-193, users should apply the latest security patches provided by the Linux Foundation for the Linux Kernel.
What type of attack does ZDI-26-193 facilitate?
ZDI-26-193 allows local attackers to disclose sensitive information through an out-of-bounds write vulnerability.
What is required for an attack exploiting ZDI-26-193 to be successful?
An attacker needs to have the ability to execute low-privileged code on the target system to exploit ZDI-26-193.
Which software is affected by ZDI-26-193?
ZDI-26-193 affects installations of the Linux Kernel maintained by the Linux Foundation.