CVE-2022-42721
Vulnerability Summary
Timeline
Description
A list management bug in BSS handling in the mac80211 stack in the Linux kernel 5.1 through 5.19.x before 5.19.16 could be used by local attackers (able to inject WLAN frames) to corrupt a linked list and, in turn, potentially execute code.
CVSS Metrics
- v3.1•MEDIUM•Score: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS Trends
Current EPSS score: 0.60%• Percentile: 47%
Techniques & Countermeasures
- CWE-835•Loop with Unreachable Exit Condition ('Infinite Loop')
The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.
Affected Systems
- alpine•linux-lts
< 5.15.74-r0 | < 5.15.74-r0 | < 5.15.74-r0 | < 5.15.74-r0 | < 5.15.74-r0 | < 5.15.74-r0 | < 5.15.74-r0 | < 5.15.74-r0 | < 5.15.74-r0 | < 5.15.74-r0
- debian•linux
< 5.10.149-1 | < 6.0.2-1 | < 6.0.2-1 | < 6.0.2-1
- ubuntu•backport-iwlwifi-dkms
all | < 8324-0ubuntu3~20.04.5 | < 9858-0ubuntu3.1 | all | all | all
- ubuntu•linux
< 5.4.0-131.147 | < 5.15.0-52.58
- ubuntu•linux-aws
< 5.4.0-1088.96 | < 5.15.0-1022.26
- ubuntu•linux-aws-5.0
all
- ubuntu•linux-aws-5.11
all
- ubuntu•linux-aws-5.13
all
- ubuntu•linux-aws-5.15
< 5.15.0-1022.26~20.04.1
- ubuntu•linux-aws-5.3
all
- ubuntu•linux-aws-5.4
< 5.4.0-1088.96~18.04.1
- ubuntu•linux-aws-5.8
all
- ubuntu•linux-aws-fips
< 5.4.0-1088.96+fips1 | all
- ubuntu•linux-azure
all | < 5.4.0-1094.100 | < 5.15.0-1022.27
- ubuntu•linux-azure-5.11
all
- ubuntu•linux-azure-5.13
all
- ubuntu•linux-azure-5.15
< 5.15.0-1022.27~20.04.1
- ubuntu•linux-azure-5.3
all
- ubuntu•linux-azure-5.4
< 5.4.0-1094.100~18.04.1
- ubuntu•linux-azure-5.8
all
- ubuntu•linux-azure-edge
all
- ubuntu•linux-azure-fde
< 5.15.0-1024.30.1
- ubuntu•linux-azure-fips
< 5.4.0-1094.100+fips1 | all
- ubuntu•linux-bluefield
all | < 5.4.0-1049.55
- ubuntu•linux-fips
< 5.4.0-1064.73 | all
- ubuntu•linux-gcp
all | < 5.4.0-1092.101 | < 5.15.0-1021.28
- ubuntu•linux-gcp-5.11
all
- ubuntu•linux-gcp-5.13
all
- ubuntu•linux-gcp-5.15
< 5.15.0-1021.28~20.04.1
- ubuntu•linux-gcp-5.3
all
- ubuntu•linux-gcp-5.4
< 5.4.0-1092.101~18.04.1
- ubuntu•linux-gcp-5.8
all
- ubuntu•linux-gcp-fips
< 5.4.0-1092.101+fips1 | all
- ubuntu•linux-gke
< 5.4.0-1086.93 | < 5.15.0-1019.23
- ubuntu•linux-gke-4.15
all
- ubuntu•linux-gke-5.15
< 5.15.0-1019.23~20.04.1
- ubuntu•linux-gke-5.4
all
- ubuntu•linux-gkeop
< 5.4.0-1056.60 | < 5.15.0-1007.10
- ubuntu•linux-gkeop-5.15
< 5.15.0-1007.10~20.04.1
- ubuntu•linux-gkeop-5.4
all
- ubuntu•linux-hwe
all
- ubuntu•linux-hwe-5.11
all
- ubuntu•linux-hwe-5.13
all
- ubuntu•linux-hwe-5.15
< 5.15.0-52.58~20.04.1
- ubuntu•linux-hwe-5.4
< 5.4.0-131.147~18.04.1
- ubuntu•linux-hwe-5.8
all
- ubuntu•linux-hwe-edge
all | all
- ubuntu•linux-ibm
< 5.4.0-1036.41 | < 5.15.0-1017.20
- ubuntu•linux-ibm-5.4
< 5.4.0-1036.41~18.04.1
- ubuntu•linux-intel-5.13
all
Showing first 50 affected entries in server-rendered view.
References (21)
- https://bugzilla.suse.com/show_bug.cgi?id=1204060
- http://www.openwall.com/lists/oss-security/2022/10/13/5
- https://git.kernel.org/pub/scm/linux/kernel/git/wireless/wireless.git/commit/?id=bcca852027e5878aec911a347407ecc88d6fff7f
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GGHENNMLCWIQV2LLA56BJNFIUZ7WB4IY/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VNN3VFQPECS6D4PS6ZWD7AFXTOSJDSSR/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/S2KTU5LFZNQS7YNGE56MT46VHMXL3DD2/
- https://www.debian.org/security/2022/dsa-5257
- https://lists.debian.org/debian-lts-announce/2022/11/msg00001.html
- http://packetstormsecurity.com/files/169951/Kernel-Live-Patch-Security-Notice-LSN-0090-1.html
- https://security.netapp.com/advisory/ntap-20230203-0008/
- https://ubuntu.com/security/CVE-2022-42721
- https://access.redhat.com/security/cve/CVE-2022-42721
- https://ubuntu.com/security/notices/USN-5691-1
- https://ubuntu.com/security/notices/USN-5692-1
- https://ubuntu.com/security/notices/USN-5693-1
- https://ubuntu.com/security/notices/USN-5700-1
- https://ubuntu.com/security/notices/USN-5708-1
- https://ubuntu.com/security/notices/USN-5752-1
- https://www.cve.org/CVERecord?id=CVE-2022-42721
- https://security-tracker.debian.org/tracker/CVE-2022-42721
- https://security.alpinelinux.org/vuln/CVE-2022-42721