CVE-2022-42721 (Medium) detected in linuxlinux-4.19.239
mend-bolt-for-github opened this issue · 1 comments
CVE-2022-42721 - Medium Severity Vulnerability
Vulnerable Library - linuxlinux-4.19.239
The Linux Kernel
Library home page: https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/?wsslib=linux
Found in HEAD commit: 8b7c061438f230c475fd8cd97a0917f6ebb9fbe0
Found in base branch: master
Vulnerability Details
A list management bug in BSS handling in the mac80211 stack in the Linux kernel 5.1 through 5.19.x before 5.19.16 could be used by local attackers (able to inject WLAN frames) to corrupt a linked list and, in turn, potentially execute code.
Publish Date: 2022-10-14
URL: CVE-2022-42721
CVSS 3 Score Details (5.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Local
- Attack Complexity: Low
- Privileges Required: Low
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: High
Suggested Fix
Type: Upgrade version
Origin: https://www.linuxkernelcves.com/cves/CVE-2022-42721
Release Date: 2022-10-14
Fix Resolution: v5.4.218,v5.10.148,v5.15.74,v5.19.16
Step up your Open Source Security Game with Mend here