CVE-2022-0322

A flaw was found in the sctp_make_strreset_req function in net/sctp/sm_make_chunk.c in the SCTP network protocol in the Linux kernel with a local user privilege access. In this flaw, an attempt to use more buffer than is allocated triggers a BUG_ON issue, leading to a denial of service (DOS).
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.15:-:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.15:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.15:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.15:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.15:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.15:rc5:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:a:oracle:communications_cloud_native_core_binding_support_function:22.1.3:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_cloud_native_core_network_exposure_function:22.1.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_cloud_native_core_policy:22.2.0:*:*:*:*:*:*:*

History

02 Feb 2023, 17:17

Type Values Removed Values Added
First Time Oracle communications Cloud Native Core Binding Support Function
Oracle communications Cloud Native Core Policy
Oracle communications Cloud Native Core Network Exposure Function
Oracle
CPE cpe:2.3:a:oracle:communications_cloud_native_core_network_exposure_function:22.1.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_cloud_native_core_policy:22.2.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_cloud_native_core_binding_support_function:22.1.3:*:*:*:*:*:*:*
References (N/A) https://www.oracle.com/security-alerts/cpujul2022.html - (N/A) https://www.oracle.com/security-alerts/cpujul2022.html - Patch, Third Party Advisory

25 Jul 2022, 18:19

Type Values Removed Values Added
References
  • (N/A) https://www.oracle.com/security-alerts/cpujul2022.html -

22 Jun 2022, 15:55

Type Values Removed Values Added
CPE cpe:2.3:a:linux:linux_kernel:5.15:rc5:*:*:*:*:*:*
cpe:2.3:a:linux:linux_kernel:5.15:-:*:*:*:*:*:*
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:a:linux:linux_kernel:5.15:rc1:*:*:*:*:*:*
cpe:2.3:a:linux:linux_kernel:5.15:rc3:*:*:*:*:*:*
cpe:2.3:a:linux:linux_kernel:5.15:rc4:*:*:*:*:*:*
cpe:2.3:a:linux:linux_kernel:5.15:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.15:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.15:-:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.15:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.15:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.15:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.15:rc3:*:*:*:*:*:*

07 Apr 2022, 14:43

Type Values Removed Values Added
CPE cpe:2.3:a:linux:linux_kernel:5.15:rc2:*:*:*:*:*:*
cpe:2.3:a:linux:linux_kernel:5.15:rc4:*:*:*:*:*:*
cpe:2.3:a:linux:linux_kernel:5.15:rc5:*:*:*:*:*:*
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:a:linux:linux_kernel:5.15:-:*:*:*:*:*:*
cpe:2.3:a:linux:linux_kernel:5.15:rc3:*:*:*:*:*:*
cpe:2.3:a:linux:linux_kernel:5.15:rc1:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
First Time Linux linux Kernel
Fedoraproject fedora
Linux
Fedoraproject
References (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=2042822 - (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=2042822 - Issue Tracking, Third Party Advisory
References (MISC) https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=a2d859e3fc97e79d907761550dbc03ff1b36479c - (MISC) https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=a2d859e3fc97e79d907761550dbc03ff1b36479c - Patch, Vendor Advisory
CWE CWE-704
CVSS v2 : unknown
v3 : unknown
v2 : 2.1
v3 : 5.5

25 Mar 2022, 19:44

Type Values Removed Values Added
New CVE

Information

Published : 2022-03-25 19:15

Updated : 2023-12-10 14:22


NVD link : CVE-2022-0322

Mitre link : CVE-2022-0322

CVE.ORG link : CVE-2022-0322


JSON object : View

Products Affected

fedoraproject

  • fedora

oracle

  • communications_cloud_native_core_policy
  • communications_cloud_native_core_network_exposure_function
  • communications_cloud_native_core_binding_support_function

linux

  • linux_kernel
CWE
CWE-704

Incorrect Type Conversion or Cast

CWE-681

Incorrect Conversion between Numeric Types