Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-3028

25
FAUCET Score

CVE-2022-3028 is a race condition in the Linux kernel's XFRM subsystem, affecting various Debian and Fedora Linux kernel versions. This flaw allows a local attacker to potentially cause an out-of-bounds write or leak kernel heap memory. Rated 7.0 HIGH, exploitation requires high attack complexity but could lead to high confidentiality, integrity, and availability impacts. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.14, < 4.9.327CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.10, < 4.14.292CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.257CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.212CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.140CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.0HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.0
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.20%
Probability of exploitation in next 30 days
EPSS Percentile
10.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0020 is in the 35th percentile among its peer group of 1,525 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (15)

github_advisorypatch availablevia nvd_reference
View patch
microsoftpatch availablevia msrc
Product: 18610-16820Fixed in: 5.10.144.1-1
microsoftpatch availablevia msrc
Product: 18617-16823Fixed in: 5.15.67.1-4
microsoftpatch availablevia msrc
Product: cbl2 kernel 5.15.67.1-4 on CBL Mariner 2.0Fixed in: 5.15.67.1-4
microsoftpatch availablevia msrc
Product: CBL Mariner 1.0 x64Fixed in: 5.10.144.1-1
microsoftpatch availablevia msrc
Product: CBL Mariner 1.0 ARMFixed in: 5.10.144.1-1
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 x64Fixed in: 5.15.67.1-4
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 ARMFixed in: 5.15.67.1-4
microsoftpatch availablevia msrc
Product: cm1 kernel 5.10.144.1-1 on CBL Mariner 1.0Fixed in: 5.10.144.1-1
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt-0:4.18.0-477.10.1.rt7.274.el8_8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-0:4.18.0-477.10.1.el8_8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Extended Update SupportFixed in: kernel-0:4.18.0-372.87.1.el8_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt-0:5.14.0-284.11.1.rt14.296.el9_2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-0:5.14.0-284.11.1.el9_2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Virtualization 4 for Red Hat Enterprise Linux 8Fixed in: kernel-0:4.18.0-372.87.1.el8_6
View patch

Vendor Advisories (3)

microsoft2022-Sep/CVE-2022-3028

CVE-2022-3028

Sep 13, 2022
microsoft2022-Aug/CVE-2022-3028Important

A race condition was found in the Linux kernel's IP framework for transforming packets (XFRM subsystem) when multiple calls to xfrm_probe_algs occurred simultaneously. This flaw could allow a local attacker to potentially trigger an out-of-bounds write or leak kernel heap memory by performing an out-of-bounds read and copying it into a socket.

Aug 9, 2022
redhatCVE-2022-3028Moderate

kernel: race condition in xfrm_probe_algs can lead to OOB read/write

Jul 21, 2022

References

github.com / torvalds/linux/commit/ba953a9d89a00c078b85f4b190bc1dde66fe16b5
PatchThird Party Advisory
lists.debian.org / debian-lts-announce/2022/10/msg00000.html
Mailing ListThird Party Advisory
lists.debian.org / debian-lts-announce/2022/11/msg00001.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/F3MYP7WX4PNE6RCITVXA43CECBZT4CL6
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/JKVA75UHKVOHNOEPCLUHTFGWCOOUBDM3
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/PEQYVCNYUWB4CJ2YRAYNF2GGFQ7SUYC4
lore.kernel.org / all/YtoWqEkKzvimzWS5%40gondor.apana.org.au/T
security.netapp.com / advisory/ntap-20230214-0004
Third Party Advisory