UBUNTU-CVE-2022-36946
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-36946
UBUNTU-CVE-2022-36946
Summary:
Details: nfqnl_mangle in net/netfilter/nfnetlink_queue.c in the Linux kernel through 5.18.14 allows remote attackers to cause a denial of service (panic) because, in the case of an nf_queue verdict with a one-byte nfta_payload attribute, an skb_pull can encounter a negative skb->len.
References: https://ubuntu.com/security/CVE-2022-36946, https://marc.info/?l=netfilter-devel&m=165883202007292&w=2, https://ubuntu.com/security/notices/USN-5580-1, https://ubuntu.com/security/notices/USN-5590-1, https://ubuntu.com/security/notices/USN-5621-1, https://ubuntu.com/security/notices/USN-5622-1, https://ubuntu.com/security/notices/USN-5623-1, https://ubuntu.com/security/notices/USN-5624-1, https://ubuntu.com/security/notices/USN-5630-1, https://ubuntu.com/security/notices/USN-5633-1, https://ubuntu.com/security/notices/USN-5634-1, https://ubuntu.com/security/notices/USN-5635-1, https://ubuntu.com/security/notices/USN-5639-1, https://ubuntu.com/security/notices/USN-5640-1, https://ubuntu.com/security/notices/USN-5644-1, https://ubuntu.com/security/notices/USN-5647-1, https://ubuntu.com/security/notices/USN-5648-1, https://ubuntu.com/security/notices/USN-5650-1, https://ubuntu.com/security/notices/USN-5652-1, https://ubuntu.com/security/notices/USN-5654-1, https://ubuntu.com/security/notices/USN-5655-1, https://ubuntu.com/security/notices/USN-5660-1, https://ubuntu.com/security/notices/USN-5683-1, https://www.cve.org/CVERecord?id=CVE-2022-36946
Affected packages
Package
Name: linux-aws
Purl: pkg:deb/ubuntu/linux-aws?arch=source&distro=trusty%2Fesm
Affected ranges
Type: ECOSYSTEM
Events:
