7.8highHigh
CVE-2022-32981
Linux Linux Kernel
An issue was discovered in the Linux kernel through 5.18.3 on powerpc 32-bit platforms. There is a buffer overflow in ptrace PEEKUSER and POKEUSER (aka PEEKUSR and POKEUSR) when accessing floating point registers.
Exploitation status
- Published references include exploit or proof-of-concept material. There is no confirmation it is being used in real attacks.
- A vendor advisory or patch reference has been published.
What the metrics mean
- It is requires local access to the machine.
- For an attacker who can reach it, no special conditions are needed to exploit it.
- To exploit it, an ordinary user account is needed.
- Beyond that, no action by a user is required.
Scoring
- CVSS
- 7.8 (v3.1)
- Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H- Weakness
- CWE-120
- Assigned by
- cve@mitre.org
Dates
- Published
- 2022-06-10
- Last modified
- 2026-08-26
- Sources
- NVD
Affected products
- Linux Linux Kernel3.13 - 4.9.318, 4.10 - 4.14.283, 4.15 - 4.19.247, 4.20 - 5.4.198, 5.5 - 5.10.122, 5.11 - 5.15.47, 5.16.0 - 5.17.15, 5.18 - 5.18.4, 5.19
As listed in the NVD configuration data. Not a statement about your estate.
References
- http://www.openwall.com/lists/oss-security/2022/06/14/3
- https://git.kernel.org/pub/scm/linux/kernel/git/powerpc/linux.git/commit/?id=8e1278444446fc97778a5e5c99bca1ce0bbc5ec9
- http://www.openwall.com/lists/oss-security/2022/06/14/3
- https://git.kernel.org/pub/scm/linux/kernel/git/powerpc/linux.git/commit/?id=8e1278444446fc97778a5e5c99bca1ce0bbc5ec9