Back

HIGH

kernel: stack overflow in do_proc_dointvec and proc_skip_spaces

Published Jan 5, 2023

Description

A stack overflow flaw was found in the Linux kernel's SYSCTL subsystem in how a user changes certain kernel parameters and variables. This flaw allows a local user to crash or potentially escalate their privileges on the system.

Affected products

Remediation

Red Hat statement

To trigger this issue, the user needs some privileges (for example, access to the sysctl files), but usually less than root or CAP_NET_ADMIN.

Red Hat mitigation

A possible workaround is preventing regular users from accessing sysctl files (such as /proc/sys/net/ipv4/tcp_rmem and similar). Also, preventing a user from increasing privileges with commands such as "unshare -rn" (that allows obtaining net namespace privileges required to access /proc/sys/net/ipv4/tcp_rmem).

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jan 5, 2023
Updated Apr 10, 2025
Reserved Dec 9, 2022
CISA Vulnrichment
Updated Apr 10, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Dec 9, 2022