AZL-8579
Dashboard / Vulnerabilities / AZL-8579
Summary: CVE-2022-0382 affecting package kernel for versions less than 5.15.26.1-1
Details: An information leak flaw was found due to uninitialized memory in the Linux kernel's TIPC protocol subsystem, in the way a user sends a TIPC datagram to one or more destinations. This flaw allows a local user to read some kernel memory. This issue is limited to no more than 7 bytes, and the user cannot control what is read. This flaw affects the Linux kernel versions prior to 5.17-rc1.
References: https://nvd.nist.gov/vuln/detail/CVE-2022-0382
Affected packages
Package
Name: kernel
Purl: pkg:rpm/azure-linux/kernel
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -5.15.26.1-1
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
