GHSA-5h7v-72v6-2r5wHighCVSS 7.8

In the Linux kernel before 5.16.15, there is a buffer overflow in ESP transformation in net/ipv4...

Published
March 24, 2022
Last Modified
September 1, 2026

🔗 CVE IDs covered (1)

📋 Description

In the Linux kernel before 5.16.15, there is a buffer overflow in ESP transformation in net/ipv4/esp4.c and net/ipv6/esp6.c via a large message. In some configurations, local users can gain privileges by overwriting kernel heap objects.

🔗 References (9)