CVE-2022-42721
Last modified
CVE-2022-42721 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. A list management bug in BSS handling in the mac80211 stack in the Linux kernel 5.1 through 5.19.x before 5.19.16 could be used by local attackers (able to inject WLAN frames) to corrupt a linked list and, in turn, potentially execute code.. EPSS estimates a 0.57% chance of exploitation in the next 30 days.
Description
A list management bug in BSS handling in the mac80211 stack in the Linux kernel 5.1 through 5.19.x before 5.19.16 could be used by local attackers (able to inject WLAN frames) to corrupt a linked list and, in turn, potentially execute code.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 5.1, < 5.19.16 |
| Fedoraproject | Fedora | 35 |
| Fedoraproject | Fedora | 36 |
| Fedoraproject | Fedora | 37 |
| Debian | Debian Linux | 10.0 |
| Debian | Debian Linux | 11.0 |
References
- http://packetstormsecurity.com/files/169951/Kernel-Live-Patch-Security-Notice-LSN-0090-1.htmlThird Party Advisory, VDB Entry
- http://www.openwall.com/lists/oss-security/2022/10/13/5Exploit, Mailing List, Third Party Advisory
- https://bugzilla.suse.com/show_bug.cgi?id=1204060Issue Tracking, Patch, Third Party Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/wireless/wireless.git/commit/?id=bcca852027e5878aec911a347407ecc88d6fff7fMailing List, Patch, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2022/11/msg00001.htmlMailing List, Third Party Advisory
- https://www.debian.org/security/2022/dsa-5257Third Party Advisory
- http://packetstormsecurity.com/files/169951/Kernel-Live-Patch-Security-Notice-LSN-0090-1.htmlThird Party Advisory, VDB Entry
- http://www.openwall.com/lists/oss-security/2022/10/13/5Exploit, Mailing List, Third Party Advisory
- https://bugzilla.suse.com/show_bug.cgi?id=1204060Issue Tracking, Patch, Third Party Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/wireless/wireless.git/commit/?id=bcca852027e5878aec911a347407ecc88d6fff7fMailing List, Patch, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2022/11/msg00001.htmlMailing List, Third Party Advisory
- https://www.debian.org/security/2022/dsa-5257Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-42721?
How severe is CVE-2022-42721?
How do I fix CVE-2022-42721?
Are you affected by CVE-2022-42721?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
