Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-0435

67
FAUCET Score

CVE-2022-0435 is a high-severity stack overflow vulnerability in the Linux kernel's TIPC protocol, affecting products like Fedora, Red Hat, and NetApp. A remote attacker can trigger this flaw by sending a maliciously crafted packet with an excessive number of domain member nodes, leading to system crashes or potential privilege escalation. With a CVSS score of 8.8 (High) and an EPSS score indicating significant exploitability, this vulnerability poses a substantial risk. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion and media coverage, suggesting awareness within the security community.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.8, < 4.9.301CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.10, < 4.14.266CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.229CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.179CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.100CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.8HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
67.99%
Probability of exploitation in next 30 days
EPSS Percentile
99.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.6799 is in the 99th percentile among its peer group of 17,822 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (21)

microsoftpatch availablevia msrc
Product: 18454-16820Fixed in: -
microsoftpatch availablevia msrc
Product: 18720-16823Fixed in: 5.15.37.1-2
microsoftpatch availablevia msrc
Product: cm1 kernel 5.10.111.1-1 on CBL Mariner 1.0Fixed in: -
microsoftpatch availablevia msrc
Product: cbl2 kernel 5.15.37.1-2 on CBL Mariner 2.0Fixed in: 5.15.37.1-2
microsoftpatch availablevia msrc
Product: CBL Mariner 1.0 x64Fixed in: 5.10.111.1-1
microsoftpatch availablevia msrc
Product: CBL Mariner 1.0 ARMFixed in: 5.10.111.1-1
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 x64Fixed in: 5.15.37.1-2
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 ARMFixed in: 5.15.37.1-2
redhatpatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Extended Update SupportFixed in: kernel-rt-0:4.18.0-305.40.1.rt7.112.el8_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Extended Update SupportFixed in: kpatch-patch
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Extended Update SupportFixed in: kernel-0:4.18.0-305.40.1.el8_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Virtualization 4 for Red Hat Enterprise Linux 8Fixed in: redhat-virtualization-host-0:4.4.10-202203101736_8.5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Extended Update SupportFixed in: kernel-0:4.18.0-193.80.1.el8_2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt-0:4.18.0-348.20.1.rt7.150.el8_5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-0:4.18.0-348.20.1.el8_5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kpatch-patch
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.1 Update Services for SAP SolutionsFixed in: kernel-0:4.18.0-147.65.1.el8_1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.1 Update Services for SAP SolutionsFixed in: kpatch-patch
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Extended Update SupportFixed in: kernel-rt-0:4.18.0-193.80.1.rt13.130.el8_2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Extended Update SupportFixed in: kpatch-patch
View patch

Vendor Advisories (3)

microsoft2022-Apr/CVE-2022-0435

CVE-2022-0435

Apr 12, 2022
microsoft2022-Mar/CVE-2022-0435Important

A stack overflow flaw was found in the Linux kernel's TIPC protocol functionality in the way a user sends a packet with malicious content where the number of domain member nodes is higher than the 64 allowed. This flaw allows a remote user to crash the system or possibly escalate their privileges if they have access to the TIPC network.

Mar 8, 2022
redhatCVE-2022-0435Important

kernel: remote stack overflow via kernel panic on systems using TIPC may lead to DoS

Feb 10, 2022

References

bugzilla.redhat.com / show_bug.cgi
Issue TrackingPatchThird Party Advisory
security.netapp.com / advisory/ntap-20220602-0001
Third Party Advisory
openwall.com / lists/oss-security/2022/02/10/1
ExploitMailing ListMitigationPatchThird Party Advisory