Related Vulnerabilities: CVE-2022-27666  

In the Linux kernel before 5.16.15, there is a buffer overflow in ESP transformation in net/ipv4/esp4.c and net/ipv6/esp6.c via a large message.

Description

The MITRE CVE dictionary describes this issue as:

In the Linux kernel before 5.16.15, there is a buffer overflow in ESP transformation in net/ipv4/esp4.c and net/ipv6/esp6.c via a large message.

Additional Information

  • Bugzilla 2067299: CVE-2022-27666 kernel: buffer overflow in ESP transformation in net/ipv4/esp4.c and net/ipv6/esp6.c via a large message
  • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
  • FAQ: Frequently asked questions about CVE-2022-27666