Lucene search

K
ubuntucveUbuntu.comUB:CVE-2022-42720
HistoryOct 14, 2022 - 12:00 a.m.

CVE-2022-42720

2022-10-1400:00:00
ubuntu.com
ubuntu.com
21
refcounting bugs
mac80211 stack
linux kernel 5.1
linux kernel 5.19.x
use-after-free
local attackers
wlan frames
code execution

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.0004 Low

EPSS

Percentile

5.1%

Various refcounting bugs in the multi-BSS handling in the mac80211 stack in
the Linux kernel 5.1 through 5.19.x before 5.19.16 could be used by local
attackers (able to inject WLAN frames) to trigger use-after-free conditions
to potentially execute code.

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.0004 Low

EPSS

Percentile

5.1%