CVE-2022-0435: fallo en kernel
Publicada el · Actualizada el
15Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackepss 68%
probabilidad de explotación
68%top 1% de las CVE
explotación observada
noninguna fuente lo reporta
Lo que declaran los fabricantes (VEX)
Declaraciones oficiales de los fabricantes en formato CSAF/VEX: si su producto está afectado, ya corregido o descartado — y por qué. Es afirmación del fabricante, no juicio de Vexday.
Red Hatdocumento VEX ↗
Corregido
14 productos (744 componentes)
Red Hat Enterprise Linux BaseOS EUS (v.8.4) · Red Hat Enterprise Linux BaseOS EUS (v. 8.2) · Red Hat Enterprise Linux BaseOS (v. 8) · Red Hat Enterprise Linux BaseOS E4S (v. 8.1) · Red Hat CodeReady Linux Builder (v. 8) · y otros 9
No afectado
4 productos (154 componentes) — porque el código vulnerable no está presente en el producto
Red Hat Enterprise Linux 9 · Red Hat Enterprise Linux 7 · Red Hat Enterprise Linux 6 · RHEL 8-based RHEV-H for RHEV 4 (build requirements)
A stack overflow flaw was found in the Linux kernel's TIPC protocol functionality in the way a user sends a packet with malicious content where the number of domain member nodes is higher than the 64 allowed. This flaw allows a remote user to crash the system or possibly escalate their privileges if they have access to the TIPC network.
Productos afectados
n/a · kernel