Overview
- Description
- The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type, which allows local users to gain privileges via a crafted perf_event_open system call.
- Source
- secalert@redhat.com
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 7.2
- Impact score
- 10
- Exploitability score
- 3.9
- Vector string
- AV:L/AC:L/Au:N/C:C/I:C/A:C
Known exploits
Data from CISA
- Vulnerability name
- Linux Kernel Privilege Escalation Vulnerability
- Exploit added on
- Sep 15, 2022
- Exploit action due
- Oct 6, 2022
- Required action
- Apply updates per vendor instructions.
Weaknesses
- nvd@nist.gov
- CWE-189
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4A84D169-58BB-49ED-A9F4-776E182C22D8", "versionEndExcluding": "3.0.75" }, { "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "88DA168C-393B-4853-8034-6E9099CC9623", "versionEndExcluding": "3.2.45", "versionStartIncluding": "3.1" }, { "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8FECB4AF-F9DF-44E3-BD62-741D5D129053", "versionEndExcluding": "3.4.42", "versionStartIncluding": "3.3" }, { "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7E3C2571-AFE5-4ED0-810D-232092DD0220", "versionEndExcluding": "3.8.9", "versionStartIncluding": "3.5" } ], "operator": "OR" } ] } ]