// For flags

CVE-2022-36879

kernel: xfrm_expand_policies() in net/xfrm/xfrm_policy.c can cause a refcount to be dropped twice

Severity Score

5.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

An issue was discovered in the Linux kernel through 5.18.14. xfrm_expand_policies in net/xfrm/xfrm_policy.c can cause a refcount to be dropped twice.

Se ha detectado un problema en el kernel de Linux versiones hasta 5.18.14. la función xfrm_expand_policies en el archivo net/xfrm/xfrm_policy.c puede causar que un refcount sea descartado dos veces

A flaw was found in the Linux kernel’s IP framework for transforming packets (XFRM subsystem). An error while resolving policies in xfrm_bundle_lookup causes the refcount to drop twice, leading to a possible crash and a denial of service.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2022-07-27 CVE Reserved
  • 2022-07-27 CVE Published
  • 2023-10-31 EPSS Updated
  • 2024-08-03 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-911: Improper Update of Reference Count
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Netapp
Search vendor "Netapp"
A700s Firmware
Search vendor "Netapp" for product "A700s Firmware"
--
Affected
in Netapp
Search vendor "Netapp"
A700s
Search vendor "Netapp" for product "A700s"
--
Safe
Netapp
Search vendor "Netapp"
Aff 8300 Firmware
Search vendor "Netapp" for product "Aff 8300 Firmware"
--
Affected
in Netapp
Search vendor "Netapp"
Aff 8300
Search vendor "Netapp" for product "Aff 8300"
--
Safe
Netapp
Search vendor "Netapp"
Fas 8300 Firmware
Search vendor "Netapp" for product "Fas 8300 Firmware"
--
Affected
in Netapp
Search vendor "Netapp"
Fas 8300
Search vendor "Netapp" for product "Fas 8300"
--
Safe
Netapp
Search vendor "Netapp"
Aff 8700 Firmware
Search vendor "Netapp" for product "Aff 8700 Firmware"
--
Affected
in Netapp
Search vendor "Netapp"
Aff 8700
Search vendor "Netapp" for product "Aff 8700"
--
Safe
Netapp
Search vendor "Netapp"
Fas 8700 Firmware
Search vendor "Netapp" for product "Fas 8700 Firmware"
--
Affected
in Netapp
Search vendor "Netapp"
Fas 8700
Search vendor "Netapp" for product "Fas 8700"
--
Safe
Netapp
Search vendor "Netapp"
Aff A400 Firmware
Search vendor "Netapp" for product "Aff A400 Firmware"
--
Affected
in Netapp
Search vendor "Netapp"
Aff A400
Search vendor "Netapp" for product "Aff A400"
--
Safe
Netapp
Search vendor "Netapp"
Fas A400 Firmware
Search vendor "Netapp" for product "Fas A400 Firmware"
--
Affected
in Netapp
Search vendor "Netapp"
Fas A400
Search vendor "Netapp" for product "Fas A400"
--
Safe
Netapp
Search vendor "Netapp"
Aff A250 Firmware
Search vendor "Netapp" for product "Aff A250 Firmware"
--
Affected
in Netapp
Search vendor "Netapp"
Aff A250
Search vendor "Netapp" for product "Aff A250"
--
Safe
Netapp
Search vendor "Netapp"
Fas A250 Firmware
Search vendor "Netapp" for product "Fas A250 Firmware"
--
Affected
in Netapp
Search vendor "Netapp"
Fas A250
Search vendor "Netapp" for product "Fas A250"
--
Safe
Netapp
Search vendor "Netapp"
Fas 500f Firmware
Search vendor "Netapp" for product "Fas 500f Firmware"
--
Affected
in Netapp
Search vendor "Netapp"
Fas 500f
Search vendor "Netapp" for product "Fas 500f"
--
Safe
Netapp
Search vendor "Netapp"
Aff 500f Firmware
Search vendor "Netapp" for product "Aff 500f Firmware"
--
Affected
in Netapp
Search vendor "Netapp"
Aff 500f
Search vendor "Netapp" for product "Aff 500f"
--
Safe
Netapp
Search vendor "Netapp"
H300s Firmware
Search vendor "Netapp" for product "H300s Firmware"
--
Affected
in Netapp
Search vendor "Netapp"
H300s
Search vendor "Netapp" for product "H300s"
--
Safe
Netapp
Search vendor "Netapp"
H500s Firmware
Search vendor "Netapp" for product "H500s Firmware"
--
Affected
in Netapp
Search vendor "Netapp"
H500s
Search vendor "Netapp" for product "H500s"
--
Safe
Netapp
Search vendor "Netapp"
H700s Firmware
Search vendor "Netapp" for product "H700s Firmware"
--
Affected
in Netapp
Search vendor "Netapp"
H700s
Search vendor "Netapp" for product "H700s"
--
Safe
Netapp
Search vendor "Netapp"
H410s Firmware
Search vendor "Netapp" for product "H410s Firmware"
--
Affected
in Netapp
Search vendor "Netapp"
H410s
Search vendor "Netapp" for product "H410s"
--
Safe
Netapp
Search vendor "Netapp"
H410c Firmware
Search vendor "Netapp" for product "H410c Firmware"
--
Affected
in Netapp
Search vendor "Netapp"
H410c
Search vendor "Netapp" for product "H410c"
--
Safe
Netapp
Search vendor "Netapp"
H610c Firmware
Search vendor "Netapp" for product "H610c Firmware"
--
Affected
in Netapp
Search vendor "Netapp"
H610c
Search vendor "Netapp" for product "H610c"
--
Safe
Netapp
Search vendor "Netapp"
H610s Firmware
Search vendor "Netapp" for product "H610s Firmware"
--
Affected
in Netapp
Search vendor "Netapp"
H610s
Search vendor "Netapp" for product "H610s"
--
Safe
Netapp
Search vendor "Netapp"
H615c Firmware
Search vendor "Netapp" for product "H615c Firmware"
--
Affected
in Netapp
Search vendor "Netapp"
H615c
Search vendor "Netapp" for product "H615c"
--
Safe
Linux
Search vendor "Linux"
Linux Kernel
Search vendor "Linux" for product "Linux Kernel"
<= 5.18.14
Search vendor "Linux" for product "Linux Kernel" and version " <= 5.18.14"
-
Affected
Debian
Search vendor "Debian"
Debian Linux
Search vendor "Debian" for product "Debian Linux"
10.0
Search vendor "Debian" for product "Debian Linux" and version "10.0"
-
Affected
Debian
Search vendor "Debian"
Debian Linux
Search vendor "Debian" for product "Debian Linux"
11.0
Search vendor "Debian" for product "Debian Linux" and version "11.0"
-
Affected
Netapp
Search vendor "Netapp"
Active Iq Unified Manager
Search vendor "Netapp" for product "Active Iq Unified Manager"
-vmware_vsphere
Affected
Netapp
Search vendor "Netapp"
E-series Santricity Os Controller
Search vendor "Netapp" for product "E-series Santricity Os Controller"
>= 11.0 <= 11.50.2
Search vendor "Netapp" for product "E-series Santricity Os Controller" and version " >= 11.0 <= 11.50.2"
-
Affected
Netapp
Search vendor "Netapp"
Hci Bootstrap Os
Search vendor "Netapp" for product "Hci Bootstrap Os"
--
Affected