Lucene search

K
osvGoogleOSV:ASB-A-253641805
HistoryJan 01, 2023 - 12:00 a.m.

: fix u8 overflow in cfg80211_update_notlisted_nontrans

2023-01-0100:00:00
Google
osv.dev
5
integer overflow
out of bounds write
remote code execution
software vulnerability
no user interaction

8.1 High

CVSS3

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

8.4 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

56.4%

In cfg80211_update_notlisted_nontrans of scan.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

CPENameOperatorVersion
:linux_kernel:eqKernel

References

8.1 High

CVSS3

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

8.4 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

56.4%