peter bassill · operator
$ cve CVE-2022-0742 JSON

CVE-2022-0742

9.1
CRITICAL · CVSS 3.1 · EPSS 5% (pctl 92)

In your normal cycle

Critical by CVSS (9.1), but no sign of active exploitation.

Description

Memory leak in icmp6 implementation in Linux Kernel 5.13+ allows a remote attacker to DoS a host by making it go out-of-memory via icmp6 packets of type 130 or 131. We recommend upgrading past commit 2d3916f3189172d5c69d33065c3c21119fe539fc.

Scoring

CVSS9.1 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
EPSS5.04% — more likely to be exploited than 92% of all CVEs
WeaknessCWE-275
On CISA KEVno
Public exploitnone known
Published2022-03-18
Last modified2026-06-17

Affected (27)

VendorProduct
linuxlinux kernel
netappa400
netappa400 firmware
netappaff 8300
netappaff 8300 firmware
netappaff 8700
netappaff 8700 firmware
netappfas 8300
netappfas 8300 firmware
netappfas 8700
netappfas 8700 firmware
netapph300e
netapph300e firmware
netapph300s
netapph300s firmware
netapph410c
netapph410c firmware
netapph410s
netapph410s firmware
netapph500e
netapph500e firmware
netapph500s
netapph500s firmware
netapph700e
netapph700e firmware
netapph700s
netapph700s firmware

References

→ the Explorer  ·  watch your stack  ·  NVD