CVE-2022-27666High· 7.8▾ MidnightPoC availableA heap buffer overflow flaw was found in IPsec ESP transformation code in net/ipv4/esp4.c and net/ipv6/esp6.c. This flaw allows a local attacker with a normal user privilege to overwrite kernel heap objects and may cause a local privileg…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 42.9 · likelihood 1.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Sep 1.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
5.5%
3 GitHub repos
A heap buffer overflow flaw was found in IPsec ESP transformation code in net/ipv4/esp4.c and net/ipv6/esp6.c. This flaw allows a local attacker with a normal user privilege to overwrite kernel heap objects and may cause a local privilege escalation threat.
linux_kernel >= 4.11, < 4.14.274linux_kernel >= 4.15, < 4.19.237linux_kernel >= 4.20, < 5.4.188linux_kernel >= 5.5, < 5.10.108linux_kernel >= 5.11, < 5.15.29linux_kernel >= 5.16, < 5.16.15linux_kernel = 5.17fedora = 34fedora = 35virtualization = 4.0enterprise_linux = 8.0h300s_firmwareh500s_firmwareh700s_firmwareh300e_firmwareh500e_firmwareh700e_firmwareh410s_firmwareh410c_firmwaredebian_linux = 9.0debian_linux = 10.0debian_linux = 11.0Upgrade past the affected range:
linux_kernel 5.16.15Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2022-0995High· 7.8An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem
CVE-2021-3501High· 7.1A flaw was found in the Linux kernel in versions before 5.12
CVE-2020-1054High· 7.0An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory
CVE-2021-4034High· 7.8A local privilege escalation vulnerability was found on polkit's pkexec utility
CVE-2022-21882High· 7.0Win32k Elevation of Privilege Vulnerability
CVE-2018-8174High· 7.5A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1…