CVE Published: 31/08/2022 |
CVE Updated: 03/08/2024 |
CVE Year: 2022 Source: redhat |
Vendor: n/a |
Product: Linux kernel Status : PUBLISHED
CVE-2022-3028 Description
A race condition was found in the Linux kernel\'s IP framework for transforming packets (XFRM subsystem) when multiple calls to xfrm_probe_algs occurred simultaneously. This flaw could allow a local attacker to potentially trigger an out-of-bounds write or leak kernel heap memory by performing an out-of-bounds read and copying it into a socket.