CVE-2022-3534
MEDIUMLinux Kernel - Use-After-Free in btf_dump_name_dups Function
Title source: llmDescription
A vulnerability classified as critical has been found in Linux Kernel. Affected is the function btf_dump_name_dups of the file tools/lib/bpf/btf_dump.c of the component libbpf. The manipulation leads to use after free. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211032.
References (3)
Core 3
Core References
Patch, Vendor Advisory
https://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf-next.git/commit/?id=93c660ca40b5d2f7c1b1626e955a8e9fa30e0749
Permissions Required, Third Party Advisory
https://vuldb.com/?id.211032
Scores
CVSS v3
5.5
EPSS
0.0053
EPSS Percentile
40.8%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-119
CWE-416
Status
published
Products (1)
linux/linux_kernel
Published
Oct 17, 2022
Tracked Since
Feb 18, 2026