CVE-2022-3545: Linux Kernel IPsec nfp_cppcore.c area_cache_get use after free
A use-after-free in the function areacacheget of the file drivers/net/ethernet/netronome/nfp/nfpcore/nfpcppcore.c of the component IPsec in Linux Kernel could allow a remote authenticated attacker from within the local network to cause an unknown impact.
Other sources
A vulnerability has been found in areacacheget in drivers/net/ethernet/netronome/nfp/nfpcore/nfpcppcore.c in IPsec in the Linux Kernel. The manipulation leads to a use after free problem.
Reference: https://git.kernel.org/pub/scm/linux/kernel/git/klassert/ipsec-next.git/commit/?id=02e1a114fdb71e59ee6770294166c30d437bf86a
— Red Hat
A vulnerability has been found in Linux Kernel and classified as critical. Affected by this vulnerability is the function areacacheget of the file drivers/net/ethernet/netronome/nfp/nfpcore/nfpcppcore.c of the component IPsec. The manipulation leads to use after free. It is recommended to apply a patch to fix this issue. The identifier VDB-211045 was assigned to this vulnerability.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-3545?
CVE-2022-3545 is classified as a vulnerability that could allow a remote authenticated attacker to cause unknown impacts.
How do I fix CVE-2022-3545?
To mitigate CVE-2022-3545, you should upgrade to kernel version 6.0 or later for Red Hat and 5.10.223-1 or later for Debian.
Which software is affected by CVE-2022-3545?
CVE-2022-3545 affects various versions of the Linux kernel, Debian Linux, and IBM Security Verify Governance components.
Can CVE-2022-3545 be exploited remotely?
Yes, CVE-2022-3545 can potentially be exploited by a remote authenticated attacker from within the same local network.
What component of the Linux Kernel does CVE-2022-3545 affect?
CVE-2022-3545 affects the IPsec component of the Linux Kernel, specifically in the function area_cache_get.