Linux Kernel IPv4 fib_semantics.c fib_nh_match out-of-bounds
Published Oct 8, 2022
5.5
MEDIUMCVSS 3.1
EPSS 5.15%
Description
A vulnerability classified as problematic has been found in Linux Kernel. This affects the function fib_nh_match of the file net/ipv4/fib_semantics.c of the component IPv4 Handler. The manipulation leads to out-of-bounds read. It is possible to initiate the attack remotely. It is recommended to apply a patch to fix this issue. The identifier VDB-210357 was assigned to this vulnerability.
Affected products
Configuration 1
- n/a
Configuration 2
- 35
- 36
- 37
Configuration 3
- 10.0
No data.
Red Hat Enterprise Linux 9
kernel-0:5.14.0-284.11.1.el9_2
Fixed · RHSA-2023:2458
Red Hat Enterprise Linux 9
kernel-0:5.14.0-284.11.1.el9_2
Fixed · RHSA-2023:2458
Red Hat Enterprise Linux 9
kernel-rt-0:5.14.0-284.11.1.rt14.296.el9_2
Fixed · RHSA-2023:2148
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-284.11.1.el9_2 | Fixed | RHSA-2023:2458 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-284.11.1.el9_2 | Fixed | RHSA-2023:2458 |
| Red Hat Enterprise Linux 9 | kernel-rt-0:5.14.0-284.11.1.rt14.296.el9_2 | Fixed | RHSA-2023:2148 |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
No known mitigation available.
References (11)
- https://access.redhat.com/security/cve/CVE-2022-3435 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2133490 Issue Tracking
- https://lists.debian.org/debian-lts-announce/2022/12/msg00031.html mailing-listMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GGHENNMLCWIQV2LLA56BJNFIUZ7WB4IY/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/S2KTU5LFZNQS7YNGE56MT46VHMXL3DD2/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VNN3VFQPECS6D4PS6ZWD7AFXTOSJDSSR/ vendor-advisory
- https://lore.kernel.org/netdev/20221005181257.8897-1-dsahern%40kernel.org/T/#u
- https://lore.kernel.org/netdev/20221005181257.8897-1-dsahern@kernel.org/T/#u
- https://nvd.nist.gov/vuln/detail/CVE-2022-3435
- https://vuldb.com/?id.210357 PatchPermissions RequiredThird Party AdvisoryVDB Entry
- https://www.cve.org/CVERecord?id=CVE-2022-3435
Change history (0)
No recorded changes yet.