CVE-2022-3623 is a high-severity race condition vulnerability affecting the Linux Kernel, specifically within the follow_page_pte function of the mm/gup.c component related to BPF. This flaw impacts various Debian Linux distributions and can be exploited remotely by an attacker with low privileges. The CVSS score of 7.5 indicates a high potential for confidentiality, integrity, and availability compromise due to the high impact and high attack complexity. Currently, there is no public exploit code available (Metasploit, Nuclei, ExploitDB), and the vulnerability has garnered minimal community discussion or media coverage, suggesting it is not under active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.1, < 5.4.228CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.5, < 5.10.159CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.11, < 5.15.78CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.16, < 5.19.17CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.0, < 6.0.3CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.