CVE-2022-41674
An issue was discovered in the Linux kernel before 5.19.16. Attackers able to inject WLAN frames could cause a buffer overflow in the ieee80211_bss_info_update function in net/mac80211/scan.c.
02 / AFFECTED SOFTWARE
Affected packages
1 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
In cfg80211_update_notlisted_nontrans of scan.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
An issue was discovered in the Linux kernel before 5.19.16. Attackers able to inject WLAN frames could cause a buffer overflow in the ieee80211_bss_info_update function in net/mac80211/scan.c.
05 / REFERENCES
Further evidence
- https://android.googlesource.com/kernel/common/+/0a861bd25dad5
- https://android.googlesource.com/kernel/common/+/0a8ee682e4f99
- https://android.googlesource.com/kernel/common/+/21df3a583e8e0
- https://android.googlesource.com/kernel/common/+/630060f117567
- https://android.googlesource.com/kernel/common/+/7d998f6b7365d
- https://android.googlesource.com/kernel/common/+/864f2d3482f4b
- https://android.googlesource.com/kernel/common/+/93a3a32554079
- https://android.googlesource.com/kernel/common/+/9a8ef2030510a
- https://android.googlesource.com/kernel/common/+/9e99ca59ed397
- https://android.googlesource.com/kernel/common/+/bfe29873454f3
- https://android.googlesource.com/kernel/common/+/d15bb1f6dabe1
- https://android.googlesource.com/kernel/common/+/de124365a7d2d
- https://android.googlesource.com/kernel/common/+/fee48f3bdd751
- https://android.googlesource.com/kernel/common/+/fff244e9171b2
- https://source.android.com/security/bulletin/2023-01-01
- http://packetstormsecurity.com/files/169951/Kernel-Live-Patch-Security-Notice-LSN-0090-1.html
- http://www.openwall.com/lists/oss-security/2022/10/13/2
- https://bugzilla.suse.com/show_bug.cgi?id=1203770
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/log/net/mac80211/scan.c
- https://git.kernel.org/pub/scm/linux/kernel/git/wireless/wireless.git/commit/?id=aebe9f4639b13a1f4e9a6b42cdd2e38c617b442d
- https://lists.debian.org/debian-lts-announce/2022/11/msg00001.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GGHENNMLCWIQV2LLA56BJNFIUZ7WB4IY/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/S2KTU5LFZNQS7YNGE56MT46VHMXL3DD2/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VNN3VFQPECS6D4PS6ZWD7AFXTOSJDSSR/
- https://www.debian.org/security/2022/dsa-5257
- https://www.openwall.com/lists/oss-security/2022/10/13/5