PT-2022-1381 · Linux+6 · Linux Kernel+6
Soenke Huster
·
Published
2022-10-10
·
Updated
2025-05-15
·
CVE-2022-42719
CVSS v3.1
8.8
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions 5.2 through 5.19.x before 5.19.16
Description
A use-after-free issue in the mac80211 stack when parsing a multi-BSSID element could be exploited by attackers able to inject WLAN frames to crash the kernel and potentially execute code. This issue is related to a logic error in the code, specifically in the
ieee802 11 parse elems crc function of util.c, which could lead to remote code execution without additional execution privileges needed. User interaction is not required for exploitation.Recommendations
For Linux kernel versions 5.2 through 5.19.x before 5.19.16, update to version 5.19.16 or later to resolve the issue. As a temporary workaround, consider restricting access to WLAN frames to minimize the risk of exploitation. Additionally, ensure that any code using the
ieee802 11 parse elems crc function is reviewed and updated to prevent potential use-after-free errors.Exploit
Fix
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu