CVE-2022-1353
HighA vulnerability was found in the pfkey_register function in net/key/af_key.c in the Linux kernel. This flaw allows a local, unprivileged user to gain access to kernel memory, leading to a system crash or a leak of internal kernel information.
CVSS 3.1 score
7.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Weakness type
CWE-200CVE-2022-1353 is a Information Exposure vulnerability
What is Information Exposure?
The product exposes sensitive information to an actor not authorised to see it. Learn more on MITRE CWE
Affected versions
Linux kernel versions
4.10,
4.15,
4.20,
5.5,
5.11,
5.16
and later are affected. Fixed in
4.14.276,
4.19.238,
5.4.189,
5.10.110,
5.15.33,
5.16.19
and their respective stable series.
References
6 total-
Issue Tracking Patch Third Party Advisory
-
Patch Third Party Advisory
-
Mailing List Third Party Advisory
-
Third Party Advisory
-
Debian Securityhttps://www.debian.org/security/2022/dsa-5127Third Party Advisory
Frequently asked questions
-
What is CVE-2022-1353?
CVE-2022-1353 is a High severity Linux kernel vulnerability with a CVSS score of 7.1 out of 10 , classified as an Information Exposure flaw (CWE-200) . It affects Linux kernel versions from 4.10 onward and has been patched in 4.14.276, 4.19.238, 5.4.189 and others. CVE-2022-1353 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.
-
What is the CVSS score for CVE-2022-1353?
CVE-2022-1353 has a CVSS score of 7.1 out of 10, rated High severity (CVSS 3.1). The vector string is
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H. -
Is there a patch available for CVE-2022-1353?
Yes. CVE-2022-1353 has been patched. Fixed versions include 4.14.276, 4.19.238, 5.4.189 and others. If you are running Linux kernel 4.10 or later up to the fix versions, apply the relevant patch for your kernel branch.
-
Is CVE-2022-1353 actively exploited?
No. CVE-2022-1353 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.