Database/Kernel, userspace & hypervisor
Linux kernel (eBPF verifier): kernel/bpf/verifier.c mishandles pointer types - unprivileged BPF to local root
CVSS 6.7CVE-2022-23222Kernel, userspace & hypervisorcurated
Impact
kernel/bpf/verifier.c mishandles pointer types - unprivileged BPF to local root
Who can reach it
Any tenant process in a container where unprivileged BPF is enabled
What to do
Livepatchable; otherwise drain + reboot. kernel.unprivileged_bpf_disabled=1
References
Related entries
- Linux kernel (eBPF verifier): Incorrect verifier pruning marks unsafe paths as safeCVE-2023-2163 · Linux kernel (eBPF verifier)High
- Linux kernel (eBPF verifier): eBPF ALU32 bitwise-op bounds tracking flawCVE-2021-3490 · Linux kernel (eBPF verifier)High
- Linux kernel (nf_tables): Cross-table use-after-free in nf_tables leading to local privilege escalationCVE-2022-2586 · Linux kernel (nf_tables)Medium
- Xen (x86 PV): Insufficient care with non-coherent mappings - PV guest to host compromiseCVE-2022-26363 · Xen (x86 PV)Medium
- Linux kernel (drivers/pci/pcie): The ASPM link state keeps a raw pointer to function 0 of a multi-function device.CVE-2023-53446 · Linux kernel (drivers/pci/pcie)Medium
- Intel oneAPI Math Kernel Library (oneMKL): An uncontrolled library search path: the component loads a shared libraryCVE-2024-21766 · Intel oneAPI Math Kernel Library (oneMKL)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.