CVE-2022-0500

:linux_kernel:: Improper Restriction of Operations within the Bounds of a Memory Buffer (CVE-2022-0500)

Affected

  • android/:linux_kernel: :0..*
  • android/:linux_kernel: Kernel..*

Description

A flaw was found in unrestricted eBPF usage by the BPF_BTF_LOAD, leading to a possible out-of-bounds memory write in the Linux kernel’s BPF subsystem due to the way a user loads BTF. This flaw allows a local user to crash or escalate their privileges on the system.

Affected operating systems

  • linux

    linux / linux_kernel

  • other

    fedoraproject / fedora34

  • other

    fedoraproject / fedora35

  • other

    netapp / h300e_firmware

  • other

    netapp / h300s_firmware

  • other

    netapp / h410c_firmware

  • other

    netapp / h410s_firmware

  • other

    netapp / h500e_firmware

  • other

    netapp / h500s_firmware

  • other

    netapp / h700e_firmware

  • other

    netapp / h700s_firmware

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

android:linux_kernel:
:0Kernel

Metrics

7.8
Source: nvd-v3
27.2 %
Elevated — this CVE ranks above at least 10% of all CVEs scored today.
Show all metrics
Severity
high
no public PoC known
0.4 %
Low — model estimates < 1% exploitation likelihood.
Published
2022-03-25 18:03 UTC
CWE-119, CWE-787

Weakness classes (CWE)

  • CWE-119Class

    Improper Restriction of Operations within the Bounds of a Memory Buffer

    The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

    cwe.mitre.org →
  • CWE-787Base

    Out-of-bounds Write

    The product writes data past the end, or before the beginning, of the intended buffer.

    cwe.mitre.org →

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-10-08 22:17 UTC· secalert@redhat.com
    • Reference: https://bugzilla.redhat.com/show_bug.cgi?id=2044578
    • Reference: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=20b2aff4bc15bda809f994761d5719827d66c0b4
    • Reference: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=216e3cd2f28dbbf1fe86848e0e29e6693b9f0a20
    • Reference: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=34d3a78c681e8e7844b43d1a2f4671a04249c821
  2. CVE Modified2026-10-08 22:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2022-0500","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalIm…
  3. CVE Modified2026-10-08 22:17 UTC· af854a3a-2127-422b-91ae-364da2661108
    • Reference: https://bugzilla.redhat.com/show_bug.cgi?id=2044578
    • Reference: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=20b2aff4bc15bda809f994761d5719827d66c0b4
    • Reference: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=216e3cd2f28dbbf1fe86848e0e29e6693b9f0a20
    • Reference: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=34d3a78c681e8e7844b43d1a2f4671a04249c821