A race condition was found in the Linux kernel's IP framework for transforming packets (XFRM subsystem) when multiple calls to xfrmprobealgs occurred simultaneously. This flaw could allow a local attacker to potentially trigger an out-of-bounds write or leak kernel heap memory by performing an out-of-bounds read and copying it into a socket.
[
{
"deprecated": false,
"target": {
"function": "pfkey_register",
"file": "net/key/af_key.c"
},
"source": "https://github.com/torvalds/linux/commit/ba953a9d89a00c078b85f4b190bc1dde66fe16b5",
"digest": {
"function_hash": "42587898170240785244862521570080400260",
"length": 728.0
},
"signature_type": "Function",
"signature_version": "v1",
"id": "CVE-2022-3028-01c8c957"
},
{
"deprecated": false,
"target": {
"file": "net/key/af_key.c"
},
"source": "https://github.com/torvalds/linux/commit/ba953a9d89a00c078b85f4b190bc1dde66fe16b5",
"digest": {
"line_hashes": [
"203362748891142423608531699847482221659",
"24165639575998487897530665472036786655",
"4644214989902488476893742154780380563",
"77501090310681261257112516847311482860",
"147177710874407006680207049966535368107"
],
"threshold": 0.9
},
"signature_type": "Line",
"signature_version": "v1",
"id": "CVE-2022-3028-5a3767c1"
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-3028.json"