CVE-2022-3534
Publication date 17 October 2022
Last updated 7 August 2026
Ubuntu priority
Cvss 3 Severity Score
Description
A vulnerability has been found in Linux Kernel up to 5.10.162/5.15.85/6.0.15/6.1.1. The impacted element is the function btf_dump_name_dups of the file tools/lib/bpf/btf_dump.c of the component libbpf. The manipulation leads to use after free. Upgrading to version 5.10.163, 5.15.86, 6.0.16, 6.1.2 and 6.2 is sufficient to resolve this issue. The identifier of the patch is c61650b869e0b6fb0c0a28ed42d928eea969afc8/fbe08093fb2334549859829ef81d42570812597d/8c64a8e76eb85d422af5ec60ccbf26e3ead8c333/a733bf10198eb5bb927890940de8ab457491ed3b/93c660ca40b5d2f7c1b1626e955a8e9fa30e0749. You should upgrade the affected component.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| libbpf | 26.04 LTS resolute |
Fixed 1.0.1-2ubuntu1
|
| 24.04 LTS noble |
Fixed 1.0.1-2ubuntu1
|
|
| 22.04 LTS jammy |
Fixed 0.5.0-1ubuntu22.04.1
|
|
| 20.04 LTS focal |
Fixed 0.5.0-1~ubuntu20.04.1+esm1
|
|
| 18.04 LTS bionic | Not in release | |
| 16.04 LTS xenial | Not in release | |
| 14.04 LTS trusty | Not in release | |
| dwarves-dfsg | 26.04 LTS resolute | Not in release |
| 24.04 LTS noble | Not in release | |
| 22.04 LTS jammy | Not in release | |
| 20.04 LTS focal |
Fixed 1.21-0ubuntu1~20.04.1
|
|
| 18.04 LTS bionic |
Fixed 1.21-0ubuntu1~18.04.1+esm1
|
|
| 16.04 LTS xenial | Ignored end of standard support | |
| 14.04 LTS trusty | Ignored end of standard support |
Get expanded security coverage with Ubuntu Pro
Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.
Get Ubuntu Pro 30-day free trialNotes
mdeslaur
introduced by: https://github.com/libbpf/libbpf/commit/7ac1547f32f060d84b06c74edbb2c6896cc07949
Severity score breakdown
CVSS version:
Base score
5.1 · Medium
Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
Base score
5.5 · Medium
Vector: CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
References
Related Ubuntu Security Notices (USN)
- USN-5759-1
- LibBPF vulnerabilities
- 5 December 2022
- USN-5759-2
- LibBPF vulnerabilities
- 8 December 2022
- USN-6215-1
- dwarves vulnerabilities
- 11 July 2023