CVE-2022-42721
A list management bug in BSS handling in the mac80211 stack in the Linux kernel 5.1 through 5.19.x before 5.19.16 could be used by local attackers (able to inject WLAN frames) to corrupt a linked list and, in turn, potentially execute code.
02 / AFFECTED SOFTWARE
Affected packages
1 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
In cfg80211_add_nontrans_list of scan.c, there is a possible way to corrupt a list due to a logic error in the code. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
A list management bug in BSS handling in the mac80211 stack in the Linux kernel 5.1 through 5.19.x before 5.19.16 could be used by local attackers (able to inject WLAN frames) to corrupt a linked list and, in turn, potentially execute code.
05 / REFERENCES
Further evidence
- https://android.googlesource.com/kernel/common/+/0a861bd25dad5
- https://android.googlesource.com/kernel/common/+/0a8ee682e4f99
- https://android.googlesource.com/kernel/common/+/21df3a583e8e0
- https://android.googlesource.com/kernel/common/+/630060f117567
- https://android.googlesource.com/kernel/common/+/7d998f6b7365d
- https://android.googlesource.com/kernel/common/+/864f2d3482f4b
- https://android.googlesource.com/kernel/common/+/93a3a32554079
- https://android.googlesource.com/kernel/common/+/9a8ef2030510a
- https://android.googlesource.com/kernel/common/+/9e99ca59ed397
- https://android.googlesource.com/kernel/common/+/bfe29873454f3
- https://android.googlesource.com/kernel/common/+/d15bb1f6dabe1
- https://android.googlesource.com/kernel/common/+/de124365a7d2d
- https://android.googlesource.com/kernel/common/+/fee48f3bdd751
- https://android.googlesource.com/kernel/common/+/fff244e9171b2
- https://source.android.com/security/bulletin/2023-01-01
- http://packetstormsecurity.com/files/169951/Kernel-Live-Patch-Security-Notice-LSN-0090-1.html
- http://www.openwall.com/lists/oss-security/2022/10/13/5
- https://bugzilla.suse.com/show_bug.cgi?id=1204060
- https://git.kernel.org/pub/scm/linux/kernel/git/wireless/wireless.git/commit/?id=bcca852027e5878aec911a347407ecc88d6fff7f
- https://lists.debian.org/debian-lts-announce/2022/11/msg00001.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GGHENNMLCWIQV2LLA56BJNFIUZ7WB4IY/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/S2KTU5LFZNQS7YNGE56MT46VHMXL3DD2/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VNN3VFQPECS6D4PS6ZWD7AFXTOSJDSSR/
- https://security.netapp.com/advisory/ntap-20230203-0008/
- https://www.debian.org/security/2022/dsa-5257