CVE-2022-23222 is a flaw in the Linux kernel eBPF verifier, in the adjust_ptr_min_max_vals function in kernel/bpf/verifier.c, affecting kernels through version 5.15.14. The verifier did not apply a required sanity check when pointer arithmetic was performed on certain *_OR_NULL pointer types. This unsafe pointer handling can expose kernel memory and undermine verifier-enforced memory-safety constraints, enabling a local attacker to obtain kernel information and potentially escalate privileges.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a local privilege escalation exploit for CVE-2022-23222, a vulnerability in the Linux kernel's eBPF subsystem. The main exploit logic is implemented in 'exploit.c', which orchestrates a multi-phase attack: it creates eBPF maps, leaks kernel addresses, prepares arbitrary read/write primitives, locates the current process's credentials in kernel memory, and overwrites them to gain root privileges. The exploit then spawns a root shell. The supporting header files provide eBPF instruction macros, configuration constants, debugging utilities, and helper functions. The exploit is operational and provides a working root shell if run on a vulnerable system. The only fingerprintable endpoint is the use of '/dev/urandom' for random number generation. The exploit is not part of a framework and is a standalone C program targeting Linux systems with a vulnerable kernel.
This repository contains a proof-of-concept (POC) local privilege escalation exploit for CVE-2022-23222, targeting the Linux kernel's eBPF subsystem. The exploit is implemented in C and consists of the following main files: 'exploit.c' (main exploit logic and entry point), 'bpf.c' (helper functions for BPF syscalls), 'bpf.h' (macros and BPF instruction helpers), and 'exploit.h' (exploit-specific constants and structures). The Makefile is provided for compilation, requiring libbpf. The exploit works by creating and manipulating eBPF maps and programs to achieve out-of-bounds read/write, ultimately modifying kernel structures to escalate privileges. Upon success, it spawns a root shell by executing '/bin/sh'. The exploit is tested on Ubuntu 20.04 with kernel 5.13.0-27-generic but may work on other vulnerable kernels. No network endpoints are involved; the attack vector is purely local. The code is a functional POC and not weaponized, as it requires manual compilation and execution on a vulnerable system.
This repository is a local privilege escalation exploit for CVE-2022-23222, a vulnerability in the Linux kernel's eBPF verifier (5.8 <= version < patched). The exploit is implemented in C (core logic in src/exploit/exploit.c) with a Rust wrapper (src/main.rs) to orchestrate the attack. Supporting files include build scripts (build.rs, build.sh), a Dockerfile for building in a containerized environment, and a Vagrantfile for setting up a vulnerable Ubuntu 21.10 VM for testing. The exploit works by abusing a flaw in the eBPF verifier's pointer type checks, allowing the attacker to gain arbitrary kernel read/write via crafted BPF programs and maps. It locates the current process's cred structure in kernel memory and overwrites UID/GID fields to escalate privileges to root, then spawns a root shell. The README provides detailed technical background, build instructions, and a step-by-step guide for testing in a virtualized lab environment. The main entry point is src/main.rs, which calls into the C exploit logic. The exploit is operational and provides a working root shell on vulnerable systems. The only fingerprintable endpoints are local file paths used for random number generation and the exploit binary location. No network or remote attack surface is present; this is a local-only exploit.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Linux kernel local privilege-escalation flaw in the BPF verifier.
Linux kernel BPF verifier local privilege-escalation vulnerability.
Linux kernel eBPF verifier flaw allowing local privilege escalation.
Security vulnerability addressed by this advisory; no technical details are provided.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.