kernel: stack overflow in do_proc_dointvec and proc_skip_spaces
Published Jan 5, 2023
7.8
HIGHCVSS 3.1
EPSS 0.43%
Description
A stack overflow flaw was found in the Linux kernel's SYSCTL subsystem in how a user changes certain kernel parameters and variables. This flaw allows a local user to crash or potentially escalate their privileges on the system.
Affected products
- Vendor n/a Product Kernel Defaultn/a
- Version kernel 6.0.12StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Kernel | n/a |
|
- ≥ 4.9.0 · ≤ 4.9.337
- ≥ 4.14.0 · ≤ 4.14.302
- ≥ 4.19.0 · ≤ 4.19.269
- ≥ 5.4.0 · ≤ 5.4.228
- ≥ 5.10.0 · ≤ 5.10.162
- ≥ 5.15.0 · ≤ 5.15.86
- ≥ 6.0.0 · ≤ 6.0.11
No data.
Red Hat Enterprise Linux 6 Extended Lifecycle Support
kernel-0:2.6.32-754.50.1.el6
Fixed · RHSA-2023:1822
Red Hat Enterprise Linux 7
kernel-0:3.10.0-1160.88.1.el7
Fixed · RHSA-2023:1091
Red Hat Enterprise Linux 7
kernel-rt-0:3.10.0-1160.88.1.rt56.1233.el7
Fixed · RHSA-2023:1092
Red Hat Enterprise Linux 7
kpatch-patch
Fixed · RHSA-2023:1101
Red Hat Enterprise Linux 7.4 Advanced Update Support
kernel-0:3.10.0-693.107.1.el7
Fixed · RHSA-2023:1706
Red Hat Enterprise Linux 7.6 Advanced Update Support
kernel-0:3.10.0-957.100.1.el7
Fixed · RHSA-2023:1705
Red Hat Enterprise Linux 7.7 Advanced Update Support
kernel-0:3.10.0-1062.71.1.el7
Fixed · RHSA-2023:0944
Red Hat Enterprise Linux 7.7 Telco Extended Update Support
kernel-0:3.10.0-1062.71.1.el7
Fixed · RHSA-2023:0944
Red Hat Enterprise Linux 7.7 Update Services for SAP Solutions
kernel-0:3.10.0-1062.71.1.el7
Fixed · RHSA-2023:0944
Red Hat Enterprise Linux 7.7 Update Services for SAP Solutions
kpatch-patch
Fixed · RHSA-2023:0945
Red Hat Enterprise Linux 8
kernel-0:4.18.0-425.19.2.el8_7
Fixed · RHSA-2023:1566
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-425.19.2.rt7.230.el8_7
Fixed · RHSA-2023:1584
Red Hat Enterprise Linux 8
kpatch-patch
Fixed · RHSA-2023:1659
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions
kernel-0:4.18.0-147.80.1.el8_1
Fixed · RHSA-2023:0856
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions
kpatch-patch
Fixed · RHSA-2023:0858
Red Hat Enterprise Linux 8.2 Advanced Update Support
kernel-0:4.18.0-193.100.1.el8_2
Fixed · RHSA-2023:1109
Red Hat Enterprise Linux 8.2 Telecommunications Update Service
kernel-0:4.18.0-193.100.1.el8_2
Fixed · RHSA-2023:1109
Red Hat Enterprise Linux 8.2 Telecommunications Update Service
kernel-rt-0:4.18.0-193.100.1.rt13.151.el8_2
Fixed · RHSA-2023:1110
Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions
kernel-0:4.18.0-193.100.1.el8_2
Fixed · RHSA-2023:1109
Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions
kpatch-patch
Fixed · RHSA-2023:1103
Red Hat Enterprise Linux 8.4 Extended Update Support
kernel-0:4.18.0-305.82.1.el8_4
Fixed · RHSA-2023:1221
Red Hat Enterprise Linux 8.4 Extended Update Support
kernel-rt-0:4.18.0-305.82.1.rt7.154.el8_4
Fixed · RHSA-2023:1220
Red Hat Enterprise Linux 8.4 Extended Update Support
kpatch-patch
Fixed · RHSA-2023:1251
Red Hat Enterprise Linux 8.6 Extended Update Support
kernel-0:4.18.0-372.57.1.el8_6
Fixed · RHSA-2023:3388
Red Hat Enterprise Linux 8.6 Extended Update Support
kpatch-patch
Fixed · RHSA-2023:3431
Red Hat Enterprise Linux 9
kernel-0:5.14.0-162.18.1.el9_1
Fixed · RHSA-2023:0951
Red Hat Enterprise Linux 9
kernel-0:5.14.0-162.18.1.el9_1
Fixed · RHSA-2023:0951
Red Hat Enterprise Linux 9
kernel-rt-0:5.14.0-162.18.1.rt21.181.el9_1
Fixed · RHSA-2023:0979
Red Hat Enterprise Linux 9
kpatch-patch
Fixed · RHSA-2023:1008
Red Hat Enterprise Linux 9.0 Extended Update Support
kernel-0:5.14.0-70.49.1.el9_0
Fixed · RHSA-2023:1202
Red Hat Enterprise Linux 9.0 Extended Update Support
kernel-rt-0:5.14.0-70.49.1.rt21.120.el9_0
Fixed · RHSA-2023:1203
Red Hat Enterprise Linux 9.0 Extended Update Support
kpatch-patch
Fixed · RHSA-2023:1435
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8
kernel-0:4.18.0-372.57.1.el8_6
Fixed · RHSA-2023:3388
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8
redhat-virtualization-host-0:4.5.3-202306050942_8.6
Fixed · RHSA-2023:3491
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 Extended Lifecycle Support | kernel-0:2.6.32-754.50.1.el6 | Fixed | RHSA-2023:1822 |
| Red Hat Enterprise Linux 7 | kernel-0:3.10.0-1160.88.1.el7 | Fixed | RHSA-2023:1091 |
| Red Hat Enterprise Linux 7 | kernel-rt-0:3.10.0-1160.88.1.rt56.1233.el7 | Fixed | RHSA-2023:1092 |
| Red Hat Enterprise Linux 7 | kpatch-patch | Fixed | RHSA-2023:1101 |
| Red Hat Enterprise Linux 7.4 Advanced Update Support | kernel-0:3.10.0-693.107.1.el7 | Fixed | RHSA-2023:1706 |
| Red Hat Enterprise Linux 7.6 Advanced Update Support | kernel-0:3.10.0-957.100.1.el7 | Fixed | RHSA-2023:1705 |
| Red Hat Enterprise Linux 7.7 Advanced Update Support | kernel-0:3.10.0-1062.71.1.el7 | Fixed | RHSA-2023:0944 |
| Red Hat Enterprise Linux 7.7 Telco Extended Update Support | kernel-0:3.10.0-1062.71.1.el7 | Fixed | RHSA-2023:0944 |
| Red Hat Enterprise Linux 7.7 Update Services for SAP Solutions | kernel-0:3.10.0-1062.71.1.el7 | Fixed | RHSA-2023:0944 |
| Red Hat Enterprise Linux 7.7 Update Services for SAP Solutions | kpatch-patch | Fixed | RHSA-2023:0945 |
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-425.19.2.el8_7 | Fixed | RHSA-2023:1566 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-425.19.2.rt7.230.el8_7 | Fixed | RHSA-2023:1584 |
| Red Hat Enterprise Linux 8 | kpatch-patch | Fixed | RHSA-2023:1659 |
| Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions | kernel-0:4.18.0-147.80.1.el8_1 | Fixed | RHSA-2023:0856 |
| Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions | kpatch-patch | Fixed | RHSA-2023:0858 |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | kernel-0:4.18.0-193.100.1.el8_2 | Fixed | RHSA-2023:1109 |
| Red Hat Enterprise Linux 8.2 Telecommunications Update Service | kernel-0:4.18.0-193.100.1.el8_2 | Fixed | RHSA-2023:1109 |
| Red Hat Enterprise Linux 8.2 Telecommunications Update Service | kernel-rt-0:4.18.0-193.100.1.rt13.151.el8_2 | Fixed | RHSA-2023:1110 |
| Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions | kernel-0:4.18.0-193.100.1.el8_2 | Fixed | RHSA-2023:1109 |
| Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions | kpatch-patch | Fixed | RHSA-2023:1103 |
| Red Hat Enterprise Linux 8.4 Extended Update Support | kernel-0:4.18.0-305.82.1.el8_4 | Fixed | RHSA-2023:1221 |
| Red Hat Enterprise Linux 8.4 Extended Update Support | kernel-rt-0:4.18.0-305.82.1.rt7.154.el8_4 | Fixed | RHSA-2023:1220 |
| Red Hat Enterprise Linux 8.4 Extended Update Support | kpatch-patch | Fixed | RHSA-2023:1251 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | kernel-0:4.18.0-372.57.1.el8_6 | Fixed | RHSA-2023:3388 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | kpatch-patch | Fixed | RHSA-2023:3431 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-162.18.1.el9_1 | Fixed | RHSA-2023:0951 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-162.18.1.el9_1 | Fixed | RHSA-2023:0951 |
| Red Hat Enterprise Linux 9 | kernel-rt-0:5.14.0-162.18.1.rt21.181.el9_1 | Fixed | RHSA-2023:0979 |
| Red Hat Enterprise Linux 9 | kpatch-patch | Fixed | RHSA-2023:1008 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | kernel-0:5.14.0-70.49.1.el9_0 | Fixed | RHSA-2023:1202 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | kernel-rt-0:5.14.0-70.49.1.rt21.120.el9_0 | Fixed | RHSA-2023:1203 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | kpatch-patch | Fixed | RHSA-2023:1435 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 | kernel-0:4.18.0-372.57.1.el8_6 | Fixed | RHSA-2023:3388 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 | redhat-virtualization-host-0:4.5.3-202306050942_8.6 | Fixed | RHSA-2023:3491 |
No package ranges for this CVE.
Remediation
Red Hat statement
To trigger this issue, the user needs some privileges (for example, access to the sysctl files), but usually less than root or CAP_NET_ADMIN.
Red Hat mitigation
A possible workaround is preventing regular users from accessing sysctl files (such as /proc/sys/net/ipv4/tcp_rmem and similar). Also, preventing a user from increasing privileges with commands such as "unshare -rn" (that allows obtaining net namespace privileges required to access /proc/sys/net/ipv4/tcp_rmem).
References (8)
- http://packetstormsecurity.com/files/171289/Kernel-Live-Patch-Security-Notice-LNS-0092-1.html
- https://access.redhat.com/security/cve/CVE-2022-4378 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2152548 Issue TrackingThird Party Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/stable/stable-queue.git/tree/queue-6.0/proc-avoid-integer-type-confusion-in-get_proc_long.patch Vendor Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/stable/stable-queue.git/tree/queue-6.0/proc-proc_skip_spaces-shouldn-t-think-it-is-working-on-c-strings.patch Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-4378
- https://seclists.org/oss-sec/2022/q4/178 Mailing ListThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-4378
Change history (0)
No recorded changes yet.