Vulnerability Intelligence Report
CVE-2022-0435
A stack overflow flaw was found in the Linux kernel's TIPC protocol functionality in the way a user sends a packet with malicious content where the number of domain member nodes is higher than the 64 allowed. This flaw allows a remote user to crash the system or possibly escalate their privileges if they have access to the TIPC network.
No Active Exploit Signals
CVSS Base Score
8.8
HIGH
EPSS Probability:67.99%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-787 ↗CWE-787
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| linux | linux_kernel | 5.17 |
| redhat | codeready_linux_builder | 8.0, 8.4 |
| redhat | codeready_linux_builder_eus | 8.2 |
| redhat | codeready_linux_builder_eus_for_power_little_endian | 8.2 |
| redhat | codeready_linux_builder_for_power_little_endian_eus | 8.0, 8.4 |
| redhat | enterprise_linux | 8.0 |
| redhat | enterprise_linux_eus | 8.2, 8.4 |
| redhat | enterprise_linux_for_ibm_z_systems | 8.0 |
| redhat | enterprise_linux_for_ibm_z_systems_eus | 8.2, 8.4 |
| redhat | enterprise_linux_for_power_little_endian | 8.0 |
| redhat | enterprise_linux_for_power_little_endian_eus | 8.2, 8.4 |
| redhat | enterprise_linux_for_real_time | 8 |
| redhat | enterprise_linux_for_real_time_for_nfv | 8 |
| redhat | enterprise_linux_for_real_time_for_nfv_tus | 8.2, 8.4 |
| redhat | enterprise_linux_for_real_time_tus | 8.2, 8.4 |
| redhat | enterprise_linux_server_aus | 8.2, 8.4 |
| redhat | enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions | 8.2, 8.4 |
| redhat | enterprise_linux_server_tus | 8.2, 8.4 |
| redhat | enterprise_linux_server_update_services_for_sap_solutions | 8.2, 8.4 |
| redhat | virtualization | 4.0 |
| redhat | virtualization_host | 4.0 |
| ovirt | node | 4.4.10 |
| fedoraproject | fedora | 34, 35 |
| netapp | h300e_firmware | all |
| netapp | h300e | all |
| netapp | h300s_firmware | all |
| netapp | h300s | all |
| netapp | h410s_firmware | all |
| netapp | h410s | all |
| netapp | h500e_firmware | all |
| netapp | h500e | all |
| netapp | h500s_firmware | all |
| netapp | h500s | all |
| netapp | h700e_firmware | all |
| netapp | h700e | all |
| netapp | h700s_firmware | all |
| netapp | h700s | all |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
67.994%
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Red Hat, Inc. · Vendor · USA |
| Reserved | 2022-01-31T00:00:00 |
| Published | 2022-03-25T00:00:00 |
| Last Updated | 2024-08-02T23:25:40 |
Community Chatter & Buzz