tr3ee/CVE-2022-23222

Operation not permitted

Opened this issue · 1 comments

I ran this on my local Linux VM and received a "-1 error operation not permitted". It's running 5.13 and I have another kernel at 5.3. I'm not sure if that means it's patched for my system?

tr3ee commented

In most cases, yes.

This vulnerability only affects kernel v5.8-5.16 (Fixed in 5.10.92 / 5.15.15 / 5.16.1)

I assume you're using Ubuntu 20.04, the kernel has been fixed by this commit "bpf: Fix out of bounds access from invalid *_or_null type verification" since 5.13.0-32.