Back

HIGH

kernel: buffer overflow in IPsec ESP transformation code

Published Mar 23, 2022

Description

A heap buffer overflow flaw was found in IPsec ESP transformation code in net/ipv4/esp4.c and net/ipv6/esp6.c. This flaw allows a local attacker with a normal user privilege to overwrite kernel heap objects and may cause a local privilege escalation threat.

Affected products

Remediation

Red Hat mitigation

The given exploit needs CAP_NET_ADMIN to set up IPsec SA and a user namespace is used to get that capability, so disabling unprivileged user namespaces gives some protection. ~~~ On non-containerized deployments of Red Hat Enterprise Linux 8, you can disable user namespaces by setting user.max_user_namespaces to 0: # echo "user.max_user_namespaces=0" > /etc/sysctl.d/userns.conf # sysctl -p /etc/sysctl.d/userns.conf On containerized deployments, such as Red Hat OpenShift Container Platform, do not use this mitigation as the functionality is needed to be enabled. ~~~ Note: If the target system is already using IPsec and has SA configured, then no additional privileges are needed to exploit the issue.

Metrics

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 23, 2022
Updated Aug 3, 2024
Reserved Mar 23, 2022
NVD
Status Analyzed
Modified Sep 1, 2026
Red Hat
Severity Important
Public date Mar 11, 2022