CVE-2022-25265

Related Vulnerabilities: CVE-2022-25265  

In the Linux kernel through 5.16.10, certain binary files may have the exec-all attribute if they were built in approximately 2003 (e.g., with GCC 3.2.2 and Linux kernel 2.4.20). This can cause execution of bytes located in supposedly non-executable regions of a file.

Description

The MITRE CVE dictionary describes this issue as:

In the Linux kernel through 5.16.10, certain binary files may have the exec-all attribute if they were built in approximately 2003 (e.g., with GCC 3.2.2 and Linux kernel 2.4.20). This can cause execution of bytes located in supposedly non-executable regions of a file.

Additional Information

  • Bugzilla 2055499: CVE-2022-25265 kernel: Executable Space Protection Bypass
  • FAQ: Frequently asked questions about CVE-2022-25265