Vulnerability Name:

CVE-2022-1679 (CCN-226853)

Assigned:2022-02-07
Published:2022-02-07
Updated:2022-12-03
Summary:A use-after-free flaw was found in the Linux kernel’s Atheros wireless adapter driver in the way a user forces the ath9k_htc_wait_for_target function to fail with some input messages. This flaw allows a local user to crash or potentially escalate their privileges on the system.
CVSS v3 Severity:7.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
7.0 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
7.0 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
6.3 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): High
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
7.0 High (REDHAT CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
6.3 Medium (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): High
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
6.0 Medium (CCN CVSS v2 Vector: AV:L/AC:H/Au:S/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): High
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-416
Vulnerability Consequences:Gain Privileges
References:Source: MITRE
Type: CNA
CVE-2022-1679

Source: XF
Type: UNKNOWN
linuxkernel-cve20221679-priv-esc(226853)

Source: secalert@redhat.com
Type: Mailing List, Third Party Advisory
secalert@redhat.com

Source: secalert@redhat.com
Type: Mailing List, Third Party Advisory
secalert@redhat.com

Source: CCN
Type: Linux Kernel Web site
ath9k: fix use-after-free in ath9k_hif_usb_rx_cb

Source: secalert@redhat.com
Type: Patch, Vendor Advisory
secalert@redhat.com

Source: secalert@redhat.com
Type: Third Party Advisory
secalert@redhat.com

Source: CCN
Type: IBM Security Bulletin 7007837 (Cloud Pak for Watson AIOps)
Multiple Vulnerabilities in CloudPak for Watson AIOPs

Vulnerable Configuration:Configuration RedHat 1:
  • cpe:/a:redhat:enterprise_linux:9:*:*:*:*:*:*:*
  • Configuration RedHat 2:
  • cpe:/a:redhat:enterprise_linux:9::nfv:*:*:*:*:*
  • Configuration RedHat 3:
  • cpe:/a:redhat:enterprise_linux:9::realtime:*:*:*:*:*
  • Configuration RedHat 4:
  • cpe:/a:redhat:enterprise_linux:9::appstream:*:*:*:*:*
  • Configuration RedHat 5:
  • cpe:/a:redhat:enterprise_linux:9::crb:*:*:*:*:*
  • Configuration RedHat 6:
  • cpe:/o:redhat:enterprise_linux:9:*:*:*:*:*:*:*
  • Configuration RedHat 7:
  • cpe:/o:redhat:enterprise_linux:9::baseos:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/o:linux:linux_kernel:-:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:8029
    P
    kernel-docs-5.14.21-150500.53.2 on GA media (Moderate)
    2023-06-20
    oval:org.opensuse.security:def:7539
    P
    kernel-64kb-5.14.21-150500.53.2 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:8090
    P
    reiserfs-kmp-default-5.14.21-150500.53.2 on GA media (Moderate)
    2023-06-12
    oval:com.redhat.rhsa:def:20228267
    P
    RHSA-2022:8267: kernel security, bug fix, and enhancement update (Moderate)
    2022-11-15
    oval:com.redhat.rhsa:def:20227933
    P
    RHSA-2022:7933: kernel-rt security and bug fix update (Moderate)
    2022-11-15
    oval:org.opensuse.security:def:118655
    P
    Security update for the Linux Kernel (Important)
    2022-08-15
    oval:org.opensuse.security:def:119468
    P
    Security update for the Linux Kernel (Important)
    2022-08-15
    oval:org.opensuse.security:def:118792
    P
    Security update for the Linux Kernel (Important)
    2022-08-15
    oval:org.opensuse.security:def:119653
    P
    Security update for the Linux Kernel (Important)
    2022-08-15
    oval:org.opensuse.security:def:118982
    P
    Security update for the Linux Kernel (Important)
    2022-08-15
    oval:org.opensuse.security:def:118235
    P
    Security update for the Linux Kernel (Important)
    2022-08-15
    oval:org.opensuse.security:def:119287
    P
    Security update for the Linux Kernel (Important)
    2022-08-15
    oval:org.opensuse.security:def:118232
    P
    Security update for the Linux Kernel (Live Patch 26 for SLE 15 SP2) (Important)
    2022-08-11
    oval:org.opensuse.security:def:4675
    P
    Security update for the Linux Kernel (Live Patch 24 for SLE 12 SP5) (Important)
    2022-08-11
    oval:org.opensuse.security:def:118233
    P
    Security update for the Linux Kernel (Live Patch 27 for SLE 15 SP2) (Important)
    2022-08-11
    oval:org.opensuse.security:def:4676
    P
    Security update for the Linux Kernel (Live Patch 22 for SLE 12 SP5) (Important)
    2022-08-11
    oval:org.opensuse.security:def:4673
    P
    Security update for the Linux Kernel (Live Patch 23 for SLE 12 SP5) (Important)
    2022-08-11
    oval:org.opensuse.security:def:118234
    P
    Security update for the Linux Kernel (Live Patch 21 for SLE 15 SP2) (Important)
    2022-08-11
    oval:org.opensuse.security:def:4674
    P
    Security update for the Linux Kernel (Live Patch 25 for SLE 12 SP5) (Important)
    2022-08-11
    oval:org.opensuse.security:def:118225
    P
    Security update for the Linux Kernel (Live Patch 18 for SLE 15 SP2) (Important)
    2022-08-10
    oval:org.opensuse.security:def:4668
    P
    Security update for the Linux Kernel (Live Patch 28 for SLE 12 SP5) (Important)
    2022-08-10
    oval:org.opensuse.security:def:118229
    P
    Security update for the Linux Kernel (Live Patch 23 for SLE 15 SP2) (Important)
    2022-08-10
    oval:org.opensuse.security:def:4672
    P
    Security update for the Linux Kernel (Live Patch 27 for SLE 12 SP5) (Important)
    2022-08-10
    oval:org.opensuse.security:def:118226
    P
    Security update for the Linux Kernel (Live Patch 24 for SLE 15 SP2) (Important)
    2022-08-10
    oval:org.opensuse.security:def:4669
    P
    Security update for the Linux Kernel (Live Patch 30 for SLE 12 SP5) (Important)
    2022-08-10
    oval:org.opensuse.security:def:118230
    P
    Security update for the Linux Kernel (Live Patch 19 for SLE 15 SP2) (Important)
    2022-08-10
    oval:org.opensuse.security:def:4666
    P
    Security update for the Linux Kernel (Live Patch 26 for SLE 12 SP5) (Important)
    2022-08-10
    oval:org.opensuse.security:def:118227
    P
    Security update for the Linux Kernel (Live Patch 25 for SLE 15 SP2) (Important)
    2022-08-10
    oval:org.opensuse.security:def:4670
    P
    Security update for the Linux Kernel (Live Patch 31 for SLE 12 SP5) (Important)
    2022-08-10
    oval:org.opensuse.security:def:118231
    P
    Security update for the Linux Kernel (Live Patch 20 for SLE 15 SP2) (Important)
    2022-08-10
    oval:org.opensuse.security:def:4667
    P
    Security update for the Linux Kernel (Live Patch 29 for SLE 12 SP5) (Important)
    2022-08-10
    oval:org.opensuse.security:def:118228
    P
    Security update for the Linux Kernel (Live Patch 22 for SLE 15 SP2) (Important)
    2022-08-10
    oval:org.opensuse.security:def:4671
    P
    Security update for the Linux Kernel (Live Patch 32 for SLE 12 SP5) (Important)
    2022-08-10
    oval:org.opensuse.security:def:125386
    P
    Security update for the Linux Kernel (Live Patch 23 for SLE 12 SP4) (Important)
    2022-08-09
    oval:org.opensuse.security:def:125387
    P
    Security update for the Linux Kernel (Live Patch 26 for SLE 12 SP4) (Important)
    2022-08-09
    oval:org.opensuse.security:def:125385
    P
    Security update for the Linux Kernel (Live Patch 25 for SLE 12 SP4) (Important)
    2022-08-09
    oval:org.opensuse.security:def:125383
    P
    Security update for the Linux Kernel (Live Patch 27 for SLE 12 SP4) (Important)
    2022-08-08
    oval:org.opensuse.security:def:125384
    P
    Security update for the Linux Kernel (Live Patch 24 for SLE 12 SP4) (Important)
    2022-08-08
    oval:org.opensuse.security:def:4737
    P
    Security update for the Linux Kernel (Important)
    2022-08-02
    oval:org.opensuse.security:def:95383
    P
    Security update for the Linux Kernel (Important)
    2022-08-01
    oval:org.opensuse.security:def:627
    P
    Security update for the Linux Kernel (Important)
    2022-08-01
    oval:org.opensuse.security:def:3753
    P
    Security update for the Linux Kernel (Important)
    2022-08-01
    oval:org.opensuse.security:def:598
    P
    Security update for the Linux Kernel (Important)
    2022-07-26
    oval:org.opensuse.security:def:43652
    P
    Security update for the Linux Kernel (Important)
    2022-07-26
    oval:org.opensuse.security:def:42421
    P
    Security update for the Linux Kernel (Important)
    2022-07-26
    oval:org.opensuse.security:def:42325
    P
    Security update for the Linux Kernel (Important)
    2022-07-26
    oval:org.opensuse.security:def:95273
    P
    Security update for the Linux Kernel (Important)
    2022-07-21
    oval:org.opensuse.security:def:93319
    P
    (Important)
    2022-07-21
    oval:org.opensuse.security:def:3783
    P
    Security update for the Linux Kernel (Important)
    2022-07-21
    oval:org.opensuse.security:def:94051
    P
    (Important)
    2022-07-21
    oval:org.opensuse.security:def:3720
    P
    Security update for the Linux Kernel (Important)
    2022-07-21
    oval:org.opensuse.security:def:95335
    P
    Security update for the Linux Kernel (Important)
    2022-07-21
    oval:org.opensuse.security:def:93477
    P
    (Important)
    2022-07-21
    oval:org.opensuse.security:def:3794
    P
    Security update for the Linux Kernel (Important)
    2022-07-21
    oval:org.opensuse.security:def:95416
    P
    Security update for the Linux Kernel (Important)
    2022-07-21
    oval:org.opensuse.security:def:94263
    P
    (Important)
    2022-07-21
    oval:org.opensuse.security:def:3726
    P
    Security update for the Linux Kernel (Important)
    2022-07-21
    oval:org.opensuse.security:def:95350
    P
    Security update for the Linux Kernel (Important)
    2022-07-21
    oval:org.opensuse.security:def:93630
    P
    (Important)
    2022-07-21
    oval:org.opensuse.security:def:3643
    P
    Security update for the Linux Kernel (Important)
    2022-07-21
    oval:org.opensuse.security:def:95427
    P
    Security update for the Linux Kernel (Important)
    2022-07-21
    oval:org.opensuse.security:def:94472
    P
    (Important)
    2022-07-21
    oval:org.opensuse.security:def:93159
    P
    (Important)
    2022-07-21
    oval:org.opensuse.security:def:95356
    P
    Security update for the Linux Kernel (Important)
    2022-07-21
    oval:org.opensuse.security:def:93837
    P
    (Important)
    2022-07-21
    oval:org.opensuse.security:def:589
    P
    Security update for the Linux Kernel (Important)
    2022-07-21
    oval:org.opensuse.security:def:3705
    P
    Security update for the Linux Kernel (Important)
    2022-07-21
    oval:org.opensuse.security:def:43645
    P
    Security update for the Linux Kernel (Important)
    2022-07-18
    oval:org.opensuse.security:def:42412
    P
    Security update for the Linux Kernel (Important)
    2022-07-18
    oval:org.opensuse.security:def:42317
    P
    Security update for the Linux Kernel (Important)
    2022-07-18
    oval:org.opensuse.security:def:582
    P
    Security update for the Linux Kernel (Important)
    2022-07-15
    oval:org.opensuse.security:def:126919
    P
    Security update for the Linux Kernel (Important)
    2022-07-14
    oval:org.opensuse.security:def:125375
    P
    Security update for the Linux Kernel (Important)
    2022-07-14
    oval:org.opensuse.security:def:127316
    P
    Security update for the Linux Kernel (Important)
    2022-07-14
    oval:org.opensuse.security:def:125755
    P
    Security update for the Linux Kernel (Important)
    2022-07-14
    oval:org.opensuse.security:def:125116
    P
    Security update for the Linux Kernel (Important)
    2022-07-14
    oval:org.opensuse.security:def:4642
    P
    Security update for the Linux Kernel (Important)
    2022-07-13
    oval:org.opensuse.security:def:6097
    P
    Security update for the Linux Kernel (Important)
    2022-07-13
    oval:org.opensuse.security:def:6344
    P
    Security update for the Linux Kernel (Important)
    2022-07-13
    oval:org.opensuse.security:def:5294
    P
    Security update for the Linux Kernel (Important)
    2022-07-13
    oval:org.opensuse.security:def:4300
    P
    Security update for the Linux Kernel (Important)
    2022-07-13
    oval:org.opensuse.security:def:6096
    P
    Security update for the Linux Kernel (Important)
    2022-07-12
    BACK
    linux linux kernel -