FlawAtlas
Search the atlas
USN-5357-2 Not scored

linux-aws-hwe, linux-azure, linux-gcp, linux-gcp-4.15, linux-oracle, linux-raspi2 vulnerability

It was discovered that the IPsec implementation in the Linux kernel did not properly allocate enough memory when performing ESP transformations, leading to a heap-based buffer overflow. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code.

Exploit probability Not scored
Published March 31, 2022
Required by Not available
Last source change June 29, 2026

02 / AFFECTED SOFTWARE

Affected packages

Ubuntu:18.04:LTS linux-gcp-4.15

34 explicit affected versions

Ubuntu:18.04:LTS linux-oracle

59 explicit affected versions

Ubuntu:18.04:LTS linux-raspi2

77 explicit affected versions

Ubuntu:Pro:14.04:LTS linux-azure

66 explicit affected versions

Ubuntu:Pro:16.04:LTS linux-aws-hwe

58 explicit affected versions

Ubuntu:Pro:16.04:LTS linux-azure

89 explicit affected versions

Ubuntu:Pro:16.04:LTS linux-gcp

81 explicit affected versions

Ubuntu:Pro:16.04:LTS linux-oracle

57 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities USN-5357-2

It was discovered that the IPsec implementation in the Linux kernel did not properly allocate enough memory when performing ESP transformations, leading to a heap-based buffer overflow. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code.

View original source

05 / REFERENCES

Further evidence