CVE-2022-27666
Executive Summary
CVE‑2022‑27666 is a heap buffer overflow in the IPsec ESP transformation code (esp4.c/esp6.c) that allows a local user to overwrite kernel heap objects, potentially leading to privilege escalation. The flaw is exploitable by normal‑privilege users on affected Linux kernels and is not yet listed in CISA KEV.
Authoritative CVE Metadata - CVSS Base Score: 7.8 (HIGH) - Published: 2022-03-23T06:15:06.717 - Last Modified: 2026-09-01T18:05:14.643
Original Description: A heap buffer overflow flaw was found in IPsec ESP transformation code in net/ipv4/esp4.c and net/ipv6/esp6.c. This flaw allows a local attacker with a normal user privilege to overwrite kernel heap objects and may cause a local privilege escalation threat.
"Using the power of decision gives you the capacity to get past any excuse to change any and every part of your life in an instant."
— Tony Robbins