Back to Database
Status published
High
CVE-2022-30594
The Linux kernel before 5.17.2 mishandles seccomp permissions. The PTRACE_SEIZE...
Vulnerability Description
The Linux kernel before 5.17.2 mishandles seccomp permissions. The PTRACE_SEIZE code path allows attackers to bypass intended restrictions on setting the PT_SUSPEND_SECCOMP flag.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-30594
Credits & Attribution
No credits recorded in the NVD database.
References
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.17.2
- https://bugs.chromium.org/p/project-zero/issues/detail?id=2276
- https://github.com/torvalds/linux/commit/ee1fee900537b5d9560e9f937402de5ddc8412f3
- https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=ee1fee900537b5d9560e9f937402de5ddc8412f3
- http://packetstormsecurity.com/files/167386/Kernel-Live-Patch-Security-Notice-LSN-0086-1.html
- https://lists.debian.org/debian-lts-announce/2022/07/msg00000.html
- https://www.debian.org/security/2022/dsa-5173
- https://security.netapp.com/advisory/ntap-20220707-0001/
- http://packetstormsecurity.com/files/170362/Linux-PT_SUSPEND_SECCOMP-Permission-Bypass-Ptracer-Death-Race.html
More from linux
View All →CVE-2022-48619
An issue was discovered in drivers/input/input.c in the Linux kernel...
Unknown
0
CVE-2022-48502
An issue was discovered in the Linux kernel before 6.2....
High
7.1
CVE-2022-48425
In the Linux kernel through 6.2.7, fs/ntfs3/inode.c has an invalid...
Unknown
0
CVE-2022-48424
In the Linux kernel before 6.1.3, fs/ntfs3/inode.c does not validate...
Unknown
0
CVE-2022-48423
In the Linux kernel before 6.1.3, fs/ntfs3/record.c does not validate...
Unknown
0
Affected Vendor
linux
View all reports →Affected Software
linux kernel, debian linux, solidfire\, enterprise sds \& hci storage node, solidfire \& hci management node, hci compute node, 8300 firmware, 8700 firmware, a400 firmware, h300s firmware, h500s firmware, h700s firmware, h410s firmware, h410c firmware
Vulnerable Versions:
0, 4.20, 5.5.0, 5.11, 5.16.0, 5.17, 9.0, 10.0
Timeline
Official Publish:
May 12th, 2022
Last Modified:
August 3rd, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.