Sploitus

CVE-2022-2639

8 known exploits for CVE-2022-2639

An integer coercion error was found in the openvswitch kernel module. Given a sufficiently large number of actions, while copying and reserving memory for a new action of a new flow, the reserve_sfa_size() function does not return -EMSGSIZE as expected, potentially leading to an out-of-bounds write access. This flaw allows a local user to crash or potentially escalate their privileges on the system.

Linux Linux Kernel
< 3.19, 4.5, 4.9.312, 4.14.277, 4.19.240, 5.4.191, 5.10.113, 5.15.36, 5.17.5
CVSS 3.1
7.8 HIGH
EPSS
0.8% (55th percentile)
Weakness
CWE-681, CWE-192
NVD status
Modified
Published
2022-09-01
CVE-2022-2639 at NVD
Authoritative description, scoring and affected products

8 known exploits for CVE-2022-2639

Proof-of-concept code and exploit modules indexed by Sploitus