{"schema_version":"1.9.0","id":"CVE-2022-0322","published":"2022-03-25T18:02:58Z","modified":"2026-08-12T03:51:28.066874943Z","related":["ALSA-2022:1988","SUSE-SU-2022:0169-1","SUSE-SU-2022:0197-1","SUSE-SU-2022:0198-1","SUSE-SU-2022:0288-1","SUSE-SU-2022:0289-1","SUSE-SU-2022:0364-1","SUSE-SU-2022:0366-1","SUSE-SU-2022:0367-1","SUSE-SU-2022:0371-1","SUSE-SU-2022:0372-1","SUSE-SU-2022:0555-1","openSUSE-SU-2022:0169-1","openSUSE-SU-2022:0198-1","openSUSE-SU-2022:0366-1"],"details":"A flaw was found in the sctp_make_strreset_req function in net/sctp/sm_make_chunk.c in the SCTP network protocol in the Linux kernel with a local user privilege access. In this flaw, an attempt to use more buffer than is allocated triggers a BUG_ON issue, leading to a denial of service (DOS).","affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git","events":[{"introduced":"519d81956ee277b4419c723adfb154603c2565ba"},{"last_affected":"519d81956ee277b4419c723adfb154603c2565ba"}],"database_specific":{"extracted_events":[{"introduced":"kernel 5.15 rc6"},{"last_affected":"kernel 5.15 rc6"}],"source":"AFFECTED_FIELD"}}],"versions":["kernel 5.15 rc6","v5.15-rc6"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-0322.json"}}],"references":[{"type":"WEB","url":"https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=a2d859e3fc97e79d907761550dbc03ff1b36479c"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpujul2022.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/0xxx/CVE-2022-0322.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-0322"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2042822"}],"database_specific":{"cna_assigner":"redhat","cwe_ids":["CWE-681"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/0xxx/CVE-2022-0322.json"}}