CVE-2022-23222

HIGH

Linux Kernel < 5.15.37 - NULL Pointer Dereference

Title source: rule
STIX 2.1

Description

kernel/bpf/verifier.c in the Linux kernel through 5.15.14 allows local users to gain privileges because of the availability of pointer arithmetic via certain *_OR_NULL pointer types.

Exploits (4)

nomisec WORKING POC 579 stars
by tr3ee · poc
https://github.com/tr3ee/CVE-2022-23222
nomisec WORKING POC 6 stars
by PenteraIO · poc
https://github.com/PenteraIO/CVE-2022-23222-POC
nomisec WORKING POC 1 stars
by FridayOrtiz · poc
https://github.com/FridayOrtiz/CVE-2022-23222
nomisec STUB
by LeoMarche · poc
https://github.com/LeoMarche/ProjetSecu

Scores

CVSS v3 7.8
EPSS 0.0111
EPSS Percentile 78.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-476
Status published
Products (12)
debian/debian_linux 11.0
fedoraproject/fedora 34
fedoraproject/fedora 35
linux/linux_kernel 5.8.0 - 5.15.37
netapp/h300e_firmware
netapp/h300s_firmware
netapp/h410c_firmware
netapp/h410s_firmware
netapp/h500e_firmware
netapp/h500s_firmware
... and 2 more
Published Jan 14, 2022
Tracked Since Feb 18, 2026