VulnerabilityModified
CVE-2022-2663
A firewall may be able to be bypassed when users are using unencrypted IRC with nf_conntrack_irc configured.
MEDIUM 5.3EPSS 3.19%
Does this matter?
Lower severity and a low EPSS score (3.19%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was found in the Linux kernel in nf_conntrack_irc where the message handling can be confused and incorrectly matches the message. A firewall may be able to be bypassed when users are using unencrypted IRC with nf_conntrack_irc configured.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 3.19% probability · 87th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-923
- Affected
- linux/linux kernel · debian/debian linux
- Source
- secalert@redhat.com
References
- https://dgl.cx/2022/08/nat-again-irc-cve-2022-2663Exploit, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/10/msg00000.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/11/msg00001.htmlMailing List, Third Party Advisory
- https://lore.kernel.org/netfilter-devel/20220826045658.100360-1-dgl%40dgl.cx/T/
- https://www.debian.org/security/2022/dsa-5257Third Party Advisory
- https://www.openwall.com/lists/oss-security/2022/08/30/1Mailing List, Third Party Advisory
- https://www.youtube.com/watch?v=WIq-YgQuYCAExploit, Third Party Advisory
- https://dgl.cx/2022/08/nat-again-irc-cve-2022-2663Exploit, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/10/msg00000.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/11/msg00001.htmlMailing List, Third Party Advisory
- https://lore.kernel.org/netfilter-devel/20220826045658.100360-1-dgl%40dgl.cx/T/
- https://www.debian.org/security/2022/dsa-5257Third Party Advisory
- https://www.openwall.com/lists/oss-security/2022/08/30/1Mailing List, Third Party Advisory
- https://www.youtube.com/watch?v=WIq-YgQuYCAExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.