An integer overflow flaw was found in the Linux kernel’s virtio device driver code in the way a user triggers the vhost_vdpa_config_validate function. This flaw allows a local user to crash or potentially escalate their privileges on the system.
References
| Link | Resource |
|---|---|
| https://lore.kernel.org/netdev/20220123001216.2460383-13-sashal@kernel.org/ | Mailing List Patch Vendor Advisory |
| http://www.openwall.com/lists/oss-security/2022/04/02/1 | Mailing List Patch Third Party Advisory |
| https://security.netapp.com/advisory/ntap-20220513-0003/ |
Configurations
Information
Published : 2022-03-30 16:15
Updated : 2022-05-13 22:15
NVD link : CVE-2022-0998
Mitre link : CVE-2022-0998
JSON object : View
Products Affected
linux
- linux_kernel
CWE
CWE-190
Integer Overflow or Wraparound
