CVE-2022-41674Out-of-bounds Write in Kernel

Severity
8.1HIGHNVD
OSV7.0OSV6.6OSV5.5
EPSS
0.5%
top 35.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 14
Latest updateJun 15

Description

An issue was discovered in the Linux kernel before 5.19.16. Attackers able to inject WLAN frames could cause a buffer overflow in the ieee80211_bss_info_update function in net/mac80211/scan.c.

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:HExploitability: 2.8 | Impact: 5.2

Affected Packages8 packages

NVDlinux/linux_kernel5.15.4.218+4
Debianlinux/linux_kernel< 5.10.149-1+3
Ubuntulinux/linux_kernel< 5.4.0-131.147+3
debiandebian/linux< linux 6.0.2-1 (bookworm)

Also affects: Debian Linux 10.0, 11.0, Fedora 35, 36, 37

Patches

🔴Vulnerability Details

11
OSV
CVE-2022-41674: In cfg80211_update_notlisted_nontrans of scan2023-01-01
OSV
linux-azure-fde vulnerabilities2022-11-30
OSV
Kernel Live Patch Security Notice2022-11-16
OSV
backport-iwlwifi-dkms vulnerabilities2022-11-01
OSV
linux-oem-5.17 vulnerabilities2022-10-19

📋Vendor Advisories

13
CISA ICS
Siemens SIMATIC S7-1500 TM MFP Linux Kernel2023-06-15
Chrome
Long Term Support Channel Update for ChromeOS: CVE-2022-416742023-01-05
Android
CVE-2022-41674: WLAN2023-01-01
Ubuntu
Linux kernel (Azure CVM) vulnerabilities2022-11-30
Ubuntu
Kernel Live Patch Security Notice2022-11-16