CVE-2022-47518Out-of-bounds Write in Kernel

CWE-787Out-of-bounds Write21 documents8 sources
Severity
7.8HIGHNVD
OSV5.5
EPSS
0.0%
top 91.50%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 18
Latest updateJun 15

Description

An issue was discovered in the Linux kernel before 6.0.11. Missing validation of the number of channels in drivers/net/wireless/microchip/wilc1000/cfg80211.c in the WILC1000 wireless driver can trigger a heap-based buffer overflow when copying the list of operating channels from Wi-Fi management frames.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages6 packages

NVDlinux/linux_kernel4.25.10.157+2
Debianlinux/linux_kernel< 5.10.158-1+3
Ubuntulinux/linux_kernel< 5.15.0-67.74
debiandebian/linux< linux 6.0.12-1 (bookworm)

Also affects: Debian Linux 10.0

Patches

🔴Vulnerability Details

8
OSV
linux-intel-iotg vulnerabilities2023-03-16
OSV
linux-kvm vulnerabilities2023-03-09
OSV
linux-gkeop vulnerabilities2023-03-08
OSV
linux-ibm, linux-raspi vulnerabilities2023-03-07
OSV
linux, linux-aws, linux-aws-5.15, linux-azure, linux-azure-5.15, linux-azure-fde, linux-gcp, linux-gcp-5.15, linux-gke, linux-gke-5.15, linux-hwe-5.15, linux-lowlatency, linux-lowlatency-hwe-5.15, lin2023-03-02

📋Vendor Advisories

12
CISA ICS
Siemens SIMATIC S7-1500 TM MFP Linux Kernel2023-06-15
Ubuntu
Linux kernel (Intel IoTG) vulnerabilities2023-03-16
Ubuntu
Linux kernel (KVM) vulnerabilities2023-03-14
Ubuntu
Linux kernel (KVM) vulnerabilities2023-03-09
Ubuntu
Linux kernel (GKE) vulnerabilities2023-03-08