Vulnerability Intelligence Report
CVE-2022-36879
An issue was discovered in the Linux kernel through 5.18.14. xfrm_expand_policies in net/xfrm/xfrm_policy.c can cause a refcount to be dropped twice.
No Active Exploit Signals
CVSS Base Score
5.5
MEDIUM
Exploitability:1.9
Impact Score:3.6
EPSS Probability:0.30%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| linux | linux_kernel | all |
| debian | debian_linux | 10.0, 11.0 |
| netapp | a700s_firmware | all |
| netapp | a700s | all |
| netapp | active_iq_unified_manager | all |
| netapp | e-series_santricity_os_controller | all |
| netapp | hci_bootstrap_os | all |
| netapp | aff_8300_firmware | all |
| netapp | aff_8300 | all |
| netapp | fas_8300_firmware | all |
| netapp | fas_8300 | all |
| netapp | aff_8700_firmware | all |
| netapp | aff_8700 | all |
| netapp | fas_8700_firmware | all |
| netapp | fas_8700 | all |
| netapp | aff_a400_firmware | all |
| netapp | aff_a400 | all |
| netapp | fas_a400_firmware | all |
| netapp | fas_a400 | all |
| netapp | aff_a250_firmware | all |
| netapp | aff_a250 | all |
| netapp | fas_a250_firmware | all |
| netapp | fas_a250 | all |
| netapp | fas_500f_firmware | all |
| netapp | fas_500f | all |
| netapp | aff_500f_firmware | all |
| netapp | aff_500f | all |
| netapp | h300s_firmware | all |
| netapp | h300s | all |
| netapp | h500s_firmware | all |
| netapp | h500s | all |
| netapp | h700s_firmware | all |
| netapp | h700s | all |
| netapp | h410s_firmware | all |
| netapp | h410s | all |
| netapp | h410c_firmware | all |
| netapp | h410c | all |
| netapp | h610c_firmware | all |
| netapp | h610c | all |
| netapp | h610s_firmware | all |
| netapp | h610s | all |
| netapp | h615c_firmware | all |
| netapp | h615c | all |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.302%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | MITRE Corporation · N/A · USA |
| Reserved | 2022-07-27T00:00:00 |
| Published | 2022-07-27T03:27:41 |
| Last Updated | 2025-05-05T16:13:47 |
Community Chatter & Buzz