CVE-2022-41674

Aliases:UBUNTU-CVE-2022-41674DEBIAN-CVE-2022-41674ALPINE-CVE-2022-41674
Advisory lineage Upstream: 0 Downstream: 34
Modified
Published: 13 Oct 2022, 00:00
Last modified:15 May 2025, 14:26

Vulnerability Summary

Overall Risk (default)
medium
43/100
CVSS Score
8.1 HIGH
v3.1 (cve.org)
EPSS Score
3.87% LOW
4% probability +3.36%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

13 Oct 2022, 00:00
Published
Vulnerability first disclosed
15 May 2025, 14:26
Last Modified
Vulnerability information updated

Description

An issue was discovered in the Linux kernel before 5.19.16. Attackers able to inject WLAN frames could cause a buffer overflow in the ieee80211_bss_info_update function in net/mac80211/scan.c.

CVSS Metrics

  • v3.1HIGHScore: 8.1CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

EPSS Trends

Current EPSS score: 3.87% Percentile: 90%

Techniques & Countermeasures

  • CWE-787Out-of-bounds Write

    The product writes data past the end, or before the beginning, of the intended buffer.

Affected Systems

  • alpinelinux-lts

    < 5.15.74-r0 | < 5.15.74-r0 | < 5.15.74-r0 | < 5.15.74-r0 | < 5.15.74-r0 | < 5.15.74-r0 | < 5.15.74-r0 | < 5.15.74-r0 | < 5.15.74-r0 | < 5.15.74-r0

  • debianlinux

    < 5.10.149-1 | < 6.0.2-1 | < 6.0.2-1 | < 6.0.2-1

  • ubuntubackport-iwlwifi-dkms

    all | < 8324-0ubuntu3~20.04.5 | < 9858-0ubuntu3.1 | all | all | all

  • ubuntulinux

    < 5.4.0-131.147 | < 5.15.0-52.58

  • ubuntulinux-aws

    < 5.4.0-1088.96 | < 5.15.0-1022.26

  • ubuntulinux-aws-5.0

    all

  • ubuntulinux-aws-5.11

    all

  • ubuntulinux-aws-5.13

    all

  • ubuntulinux-aws-5.15

    < 5.15.0-1022.26~20.04.1

  • ubuntulinux-aws-5.3

    all

  • ubuntulinux-aws-5.4

    < 5.4.0-1088.96~18.04.1

  • ubuntulinux-aws-5.8

    all

  • ubuntulinux-aws-6.2

    all

  • ubuntulinux-aws-fips

    < 5.4.0-1088.96+fips1 | all

  • ubuntulinux-azure

    all | < 5.4.0-1094.100 | < 5.15.0-1022.27

  • ubuntulinux-azure-5.11

    all

  • ubuntulinux-azure-5.13

    all

  • ubuntulinux-azure-5.15

    < 5.15.0-1022.27~20.04.1

  • ubuntulinux-azure-5.3

    all

  • ubuntulinux-azure-5.4

    < 5.4.0-1094.100~18.04.1

  • ubuntulinux-azure-5.8

    all

  • ubuntulinux-azure-edge

    all

  • ubuntulinux-azure-fde

    < 5.15.0-1024.30.1

  • ubuntulinux-azure-fips

    < 5.4.0-1094.100+fips1 | all

  • ubuntulinux-bluefield

    all | < 5.4.0-1049.55

  • ubuntulinux-fips

    < 5.4.0-1064.73 | all

  • ubuntulinux-gcp

    all | < 5.4.0-1092.101 | < 5.15.0-1021.28

  • ubuntulinux-gcp-5.11

    all

  • ubuntulinux-gcp-5.13

    all

  • ubuntulinux-gcp-5.15

    < 5.15.0-1021.28~20.04.1

  • ubuntulinux-gcp-5.3

    all

  • ubuntulinux-gcp-5.4

    < 5.4.0-1092.101~18.04.1

  • ubuntulinux-gcp-5.8

    all

  • ubuntulinux-gcp-6.2

    all

  • ubuntulinux-gcp-fips

    < 5.4.0-1092.101+fips1 | all

  • ubuntulinux-gke

    < 5.4.0-1086.93 | < 5.15.0-1019.23

  • ubuntulinux-gke-4.15

    all

  • ubuntulinux-gke-5.15

    < 5.15.0-1019.23~20.04.1

  • ubuntulinux-gke-5.4

    all

  • ubuntulinux-gkeop

    < 5.4.0-1056.60 | < 5.15.0-1007.10

  • ubuntulinux-gkeop-5.15

    < 5.15.0-1007.10~20.04.1

  • ubuntulinux-gkeop-5.4

    all

  • ubuntulinux-hwe

    all

  • ubuntulinux-hwe-5.11

    all

  • ubuntulinux-hwe-5.13

    all

  • ubuntulinux-hwe-5.15

    < 5.15.0-52.58~20.04.1

  • ubuntulinux-hwe-5.4

    < 5.4.0-131.147~18.04.1

  • ubuntulinux-hwe-5.8

    all

  • ubuntulinux-hwe-edge

    all | all

  • ubuntulinux-ibm

    < 5.4.0-1036.41 | < 5.15.0-1017.20

Showing first 50 affected entries in server-rendered view.

References (22)