CVE-2022-42722NULL Pointer Dereference in Kernel

Severity
5.5MEDIUMNVD
OSV8.1OSV7.0OSV6.6
EPSS
0.1%
top 76.71%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 14
Latest updateFeb 14

Description

In the Linux kernel 5.8 through 5.19.x before 5.19.16, local attackers able to inject WLAN frames into the mac80211 stack could cause a NULL pointer dereference denial-of-service attack against the beacon protection of P2P devices.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages7 packages

NVDlinux/linux_kernel5.85.19.16
Debianlinux/linux_kernel< 5.10.149-1+3
Ubuntulinux/linux_kernel< 5.15.0-52.58+2
debiandebian/linux< linux 6.0.2-1 (bookworm)

Also affects: Debian Linux 10.0, 11.0, Fedora 35, 36, 37

Patches

🔴Vulnerability Details

8
OSV
linux-azure-fde vulnerabilities2022-11-30
OSV
Kernel Live Patch Security Notice2022-11-16
OSV
backport-iwlwifi-dkms vulnerabilities2022-11-01
OSV
linux-oem-5.17 vulnerabilities2022-10-19
OSV
linux, linux-aws, linux-aws-5.15, linux-azure, linux-azure-5.15, linux-gcp, linux-gcp-5.15, linux-gke, linux-gke-5.15, linux-gkeop, linux-hwe-5.15, linux-ibm, linux-kvm, linux-lowlatency, linux-lowlat2022-10-19

📋Vendor Advisories

11
Palo Alto
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS2024-02-14
CISA ICS
Siemens SIMATIC S7-1500 TM MFP Linux Kernel2023-06-15
Ubuntu
Linux kernel (Azure CVM) vulnerabilities2022-11-30
Ubuntu
Kernel Live Patch Security Notice2022-11-16
Ubuntu
backport-iwlwifi-dkms vulnerabilities2022-11-01