CVE-2022-3545
MEDIUMLinux Kernel 4.11-4.14.303 - Use-After-Free in IPsec area_cache_get Function
Title source: llmDescription
A vulnerability has been found in Linux Kernel and classified as critical. Affected by this vulnerability is the function area_cache_get of the file drivers/net/ethernet/netronome/nfp/nfpcore/nfp_cppcore.c of the component IPsec. The manipulation leads to use after free. It is recommended to apply a patch to fix this issue. The identifier VDB-211045 was assigned to this vulnerability.
References (6)
Core 6
Core References
Third Party Advisory vendor-advisory
https://www.debian.org/security/2023/dsa-5324
Mailing List, Third Party Advisory mailing-list
https://lists.debian.org/debian-lts-announce/2023/03/msg00000.html
Mailing List, Third Party Advisory mailing-list
https://lists.debian.org/debian-lts-announce/2023/05/msg00006.html
Third Party Advisory
https://security.netapp.com/advisory/ntap-20221223-0003/
Third Party Advisory
https://vuldb.com/?id.211045
Scores
CVSS v3
5.5
EPSS
0.0002
EPSS Percentile
5.6%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-119
Status
published
Products (8)
debian/debian_linux
10.0
debian/debian_linux
11.0
linux/linux_kernel
4.11 - 4.14.303
netapp/h300s_firmware
netapp/h410c_firmware
netapp/h410s_firmware
netapp/h500s_firmware
netapp/h700s_firmware
Published
Oct 17, 2022
Tracked Since
Feb 18, 2026