Related Vulnerabilities: CVE-2022-26966  

An issue was discovered in the Linux kernel before 5.16.12. drivers/net/usb/sr9700.c allows attackers to obtain sensitive information from heap memory via crafted frame lengths from a device.

Description

The MITRE CVE dictionary describes this issue as:

An issue was discovered in the Linux kernel before 5.16.12. drivers/net/usb/sr9700.c allows attackers to obtain sensitive information from heap memory via crafted frame lengths from a device.

Additional Information

  • Bugzilla 2063718: CVE-2022-26966 kernel: heap memory leak in drivers/net/usb/sr9700.c
  • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
  • FAQ: Frequently asked questions about CVE-2022-26966