CVE-2022-27666
High
CVE-2022-27666
A heap buffer overflow flaw was found in IPsec ESP transformation code in net/ipv4/esp4.c and net/ipv6/esp6.c. This flaw allows a local attacker with a normal user privilege to overwrite kernel heap objects and may cause a local privilege escalation threat.
Exploit probability
5.5%
Published
March 23, 2022
Required by
Not available
Last source change
April 16, 2026
02 / AFFECTED SOFTWARE
Affected packages
1 explicit affected versions
719 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
PUB-A-227452856
View original source
Open Source Vulnerabilities
CVE-2022-27666
View original source
A heap buffer overflow flaw was found in IPsec ESP transformation code in net/ipv4/esp4.c and net/ipv6/esp6.c. This flaw allows a local attacker with a normal user privilege to overwrite kernel heap objects and may cause a local privilege escalation threat.
05 / REFERENCES
Further evidence
- https://android.googlesource.com/kernel/common/+/207e72ba41dd4389b13367c0cc2c9f157545f56a
- https://source.android.com/security/bulletin/2022-08-01
- https://bugzilla.redhat.com/show_bug.cgi?id=2061633
- https://github.com/torvalds/linux/commit/ebe48d368e97d007bfeb76fcb065d6cfc4c96645
- https://security.netapp.com/advisory/ntap-20220429-0001/
- https://www.debian.org/security/2022/dsa-5127
- https://www.debian.org/security/2022/dsa-5173