PT-2022-1381 · Linux+6 · Linux Kernel+6

Soenke Huster

·

Published

2022-10-10

·

Updated

2025-05-15

·

CVE-2022-42719

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions 5.2 through 5.19.x before 5.19.16
Description A use-after-free issue in the mac80211 stack when parsing a multi-BSSID element could be exploited by attackers able to inject WLAN frames to crash the kernel and potentially execute code. This issue is related to a logic error in the code, specifically in the ieee802 11 parse elems crc function of util.c, which could lead to remote code execution without additional execution privileges needed. User interaction is not required for exploitation.
Recommendations For Linux kernel versions 5.2 through 5.19.x before 5.19.16, update to version 5.19.16 or later to resolve the issue. As a temporary workaround, consider restricting access to WLAN frames to minimize the risk of exploitation. Additionally, ensure that any code using the ieee802 11 parse elems crc function is reviewed and updated to prevent potential use-after-free errors.

Exploit

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-2848
ALT-PU-2022-2849
ALT-PU-2022-2860
ALT-PU-2022-2877
ALT-PU-2022-2891
ALT-PU-2022-2915
ALT-PU-2022-2919
ALT-PU-2022-2951
ALT-PU-2022-2965
ALT-PU-2022-2968
ALT-PU-2022-2970
ALT-PU-2022-2975
ALT-PU-2022-3061
ALT-PU-2023-4894
ALT-PU-2023-7007
ALT-PU-2023-7682
ASB-A-253642087
AZL-11138
BDU:2022-06274
CVE-2022-42719
DLA-3173-1
DSA-5257-1
DSA-5257-2
LSN-0091-1
MGASA-2022-0379
MGASA-2022-0380
OESA-2022-2015
OPENSUSE-SU-2022_3775-1
OPENSUSE-SU-2022_3844-1
OPENSUSE-SU-2022_3897-1
OPENSUSE-SU-2022_3998-1
OPENSUSE-SU-2022_4617-1
OPENSUSE-SU-2024:12437-1
OPENSUSE-SU-2024:13704-1
ROSA-SA-2023-2189
SUSE-SU-2022:3601-1
SUSE-SU-2022:3605-1
SUSE-SU-2022:3606-1
SUSE-SU-2022:3607-1
SUSE-SU-2022:3628-1
SUSE-SU-2022:3648-1
SUSE-SU-2022:3657-1
SUSE-SU-2022:3704-1
SUSE-SU-2022:3775-1
SUSE-SU-2022:3809-1
SUSE-SU-2022:3844-1
SUSE-SU-2022:3897-1
SUSE-SU-2022:3998-1
SUSE-SU-2022:4617-1
USN-5692-1
USN-5693-1
USN-5700-1
USN-5708-1
USN-5728-1
USN-5728-2
USN-5728-3
USN-5752-1

Affected Products

Alt Linux
Astra Linux
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu