CVE-2022-0435
8.8
HIGH
CVSS 3.1
EPSS 68.0%
Description
A stack overflow flaw was found in the Linux kernel's TIPC protocol functionality in the way a user sends a packet with malicious content where the number of domain member nodes is higher than the 64 allowed. This flaw allows a remote user to crash the system or possibly escalate their privileges if they have access to the TIPC network.
How to fix CVE-2022-0435
To remediate CVE-2022-0435, upgrade the affected package to a fixed version below.
- Debian/linux—upgrade to 5.10.92-2 or later
Is CVE-2022-0435 being exploited?
Likely — EPSS is 68.0%, placing CVE-2022-0435 in the top tier of vulnerabilities by exploitation probability. Prioritise patching.
Affected packages (1)
- from 0, < 5.10.92-2
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.8 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |