PT-2022-1382 · Linux+9 · Linux Kernel+9

Soenke Huster

·

Published

2022-10-13

·

Updated

2025-05-15

·

CVE-2022-42721

CVSS v2.0

6.8

Medium

VectorAV:L/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions 5.1 through 5.19.x before 5.19.16
Description A list management bug in BSS handling in the mac80211 stack could be used by local attackers to corrupt a linked list and potentially execute code. The issue is related to a logic error in the code, which could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
Recommendations For Linux kernel versions 5.1 through 5.19.x before 5.19.16, update to version 5.19.16 or later to resolve the issue. As a temporary workaround, consider restricting access to the mac80211 stack to minimize the risk of exploitation. Avoid using the cfg80211 add nontrans list function in the scan.c file until the issue is resolved.

Exploit

Fix

DoS

Infinite Loop

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2023:2148
ALSA-2023:2458
ALSA-2023:2736
ALSA-2023:2951
ALT-PU-2022-2848
ALT-PU-2022-2860
ALT-PU-2022-2915
ALT-PU-2022-2919
ALT-PU-2023-1235
ALT-PU-2023-1684
ALT-PU-2023-1741
ALT-PU-2023-1814
ALT-PU-2023-4894
ASB-A-253642088
AZL-11117
BDU:2022-07350
CESA-2023_2736
CESA-2023_2951
CVE-2022-42721
DLA-3173-1
DSA-5257-1
DSA-5257-2
LSN-0090-1
MGASA-2022-0379
MGASA-2022-0380
OESA-2022-2015
OPENSUSE-SU-2022_3775-1
OPENSUSE-SU-2022_3844-1
OPENSUSE-SU-2022_3897-1
OPENSUSE-SU-2022_3998-1
OPENSUSE-SU-2022_4617-1
OPENSUSE-SU-2024:12437-1
OPENSUSE-SU-2024:13704-1
RHSA-2023:2148
RHSA-2023:2458
RHSA-2023:2736
RHSA-2023:2951
RHSA-2023_2148
RHSA-2023_2458
RHSA-2023_2736
RHSA-2023_2951
RHSA-2024:1188
SUSE-SU-2022:3601-1
SUSE-SU-2022:3605-1
SUSE-SU-2022:3606-1
SUSE-SU-2022:3607-1
SUSE-SU-2022:3628-1
SUSE-SU-2022:3648-1
SUSE-SU-2022:3657-1
SUSE-SU-2022:3704-1
SUSE-SU-2022:3775-1
SUSE-SU-2022:3809-1
SUSE-SU-2022:3844-1
SUSE-SU-2022:3897-1
SUSE-SU-2022:3998-1
SUSE-SU-2022:4617-1
USN-5691-1
USN-5692-1
USN-5693-1
USN-5700-1
USN-5708-1
USN-5752-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Linux Kernel
Red Hat
Red Os
Suse
Ubuntu