CVE-2022-42772
published 2022-12-06CVE-2022-42772: In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.
PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.08%
0.3th percentile
In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| unisoc_technologies_co_ltd | sc9863a_sc9832e_sc7731e_t610_t310_t606_t760_t610_t618_t606_t612_t616_t760_t770_t | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2022-42772: kernel
vendor_android·2022-12-01·CVSS 5.5
CVE-2022-42772 [MEDIUM] CVE-2022-42772: kernel
Android Security Bulletin 2022-12-01
CVE: CVE-2022-42772
Severity: HIGH
Component: kernel
References: A-253978054
U-1903041
*
GHSA
GHSA-whj7-5c9c-wvh8: In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services
ghsa_unreviewed·2022-12-06
CVE-2022-42772 [MEDIUM] CWE-787 GHSA-whj7-5c9c-wvh8: In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services
In wlan driver, there is a possible missing bounds check, This could lead to local denial of service in wlan services.
OSV
CVE-2022-20385: A wlan driver function lacks parameter checks, resulting Out-of-bounds Write issues
osv·2022-12-01
CVE-2022-20385 CVE-2022-20385: A wlan driver function lacks parameter checks, resulting Out-of-bounds Write issues
A wlan driver function lacks parameter checks, resulting Out-of-bounds Write issues.
OSV
CVE-2022-20385: a function called 'nla_parse', do not check the len of para, it will check nla_type (which can be controlled by userspace) with 'maxtype' (in this cas
osv·2022-09-01
CVE-2022-20385 CVE-2022-20385: a function called 'nla_parse', do not check the len of para, it will check nla_type (which can be controlled by userspace) with 'maxtype' (in this cas
a function called 'nla_parse', do not check the len of para, it will check nla_type (which can be controlled by userspace) with 'maxtype' (in this case, it is GSCAN_MAX), then it access polciy array 'policy[type]', which OOB access happens.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-12-06
Published