Related Vulnerabilities: CVE-2022-42719  

A use-after-free in the mac80211 stack when parsing a multi-BSSID element in the Linux kernel 5.2 through 5.19.14 could be used by remote attackers who are able to inject WLAN frames to crash the kernel and potentially execute code.

Severity Critical

Remote Yes

Type Arbitrary code execution

Description

A use-after-free in the mac80211 stack when parsing a multi-BSSID element in the Linux kernel 5.2 through 5.19.14 could be used by remote attackers who are able to inject WLAN frames to crash the kernel and potentially execute code.

AVG-2803 linux-zen 5.1-1 6.0.1.zen2-1 Critical Fixed

AVG-2802 linux-lts 5.1-1 5.15.73-3 Critical Fixed

AVG-2801 linux 5.1-1 6.0.1.arch4-1 Critical Fixed

AVG-2800 linux-hardened 5.1-1 5.19.15.hardened2-1 Critical Fixed

https://www.openwall.com/lists/oss-security/2022/10/13/2
https://www.openwall.com/lists/oss-security/2022/10/13/5
https://lore.kernel.org/netdev/20221013100522.46346-1-johannes@sipsolutions.net/T/#u
https://git.kernel.org/pub/scm/linux/kernel/git/wireless/wireless.git/commit/?id=ff05d4b45dd89b922578dac497dcabf57cf771c6
https://bugzilla.suse.com/show_bug.cgi?id=1204051