Linux Kernel BPF usdt.c parse_usdt_arg memory leak
Published Oct 17, 2022
5.7
MEDIUMCVSS 3.1
EPSS 0.40%
Description
A vulnerability was found in Linux Kernel. It has been rated as problematic. This issue affects the function parse_usdt_arg of the file tools/lib/bpf/usdt.c of the component BPF. The manipulation of the argument reg_name leads to memory leak. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-211031.
Affected products
- < 6.2
No data.
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
There was no shipped kernel version seen affected with this problem.
References (7)
- https://access.redhat.com/security/cve/CVE-2022-3533 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2165625 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-42899 Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf-next.git/commit/?id=0dc9254e03704c75f2ebc9cbef2ce4de83fba603 PatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-3533
- https://vuldb.com/?id.211031 Permissions RequiredThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-3533
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-3533 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2165625 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-42899 | Advisory | |
| https://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf-next.git/commit/?id=0dc9254e03704c75f2ebc9cbef2ce4de83fba603 | PatchVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-3533 | ||
| https://vuldb.com/?id.211031 | Permissions RequiredThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2022-3533 |
Change history (0)
No recorded changes yet.