CVE-2022-4378

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
05/01/2023
Last modified:
10/04/2025

Description

A stack overflow flaw was found in the Linux kernel's SYSCTL subsystem in how a user changes certain kernel parameters and variables. This flaw allows a local user to crash or potentially escalate their privileges on the system.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 4.9.0 (including) 4.9.337 (including)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 4.14.0 (including) 4.14.302 (including)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 4.19.0 (including) 4.19.269 (including)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.4.0 (including) 5.4.228 (including)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.10.0 (including) 5.10.162 (including)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.15.0 (including) 5.15.86 (including)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.0.0 (including) 6.0.11 (including)