kernel: use-after-free in ath9k_htc_probe_device() could cause an escalation of privileges
Published May 16, 2022
7.8
HIGHCVSS 3.1
EPSS 0.81%
Description
A use-after-free flaw was found in the Linux kernel’s Atheros wireless adapter driver in the way a user forces the ath9k_htc_wait_for_target function to fail with some input messages. This flaw allows a local user to crash or potentially escalate their privileges on the system.
Affected products
- Vendor n/a Product Kernel Defaultn/a
- Version Linux kernel 5.18-rc7StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Kernel | n/a |
|
Configuration 1
- ≥ 2.6.35 · < 4.14.291
- ≥ 4.15 · < 4.19.256
- ≥ 4.20 · < 5.4.211
- ≥ 5.5 · < 5.10.137
- ≥ 5.11 · < 5.15.61
- ≥ 5.16 · < 5.18.18
- ≥ 5.19 · < 5.19.2
Configuration 2
- 10.0
Configuration 3
- n/a
Configuration 4
- n/a
Configuration 5
- n/a
Configuration 6
- n/a
Configuration 7
- n/a
Configuration 8
- n/a
Configuration 9
- n/a
Configuration 10
- n/a
No data.
Red Hat Enterprise Linux 8
kernel-0:4.18.0-477.10.1.el8_8
Fixed · RHSA-2023:2951
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-477.10.1.rt7.274.el8_8
Fixed · RHSA-2023:2736
Red Hat Enterprise Linux 8.6 Extended Update Support
kernel-0:4.18.0-372.87.1.el8_6
Fixed · RHSA-2024:0412
Red Hat Enterprise Linux 9
kernel-0:5.14.0-162.6.1.el9_1
Fixed · RHSA-2022:8267
Red Hat Enterprise Linux 9
kernel-0:5.14.0-162.6.1.el9_1
Fixed · RHSA-2022:8267
Red Hat Enterprise Linux 9
kernel-rt-0:5.14.0-162.6.1.rt21.168.el9_1
Fixed · RHSA-2022:7933
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8
kernel-0:4.18.0-372.87.1.el8_6
Fixed · RHSA-2024:0412
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-477.10.1.el8_8 | Fixed | RHSA-2023:2951 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-477.10.1.rt7.274.el8_8 | Fixed | RHSA-2023:2736 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | kernel-0:4.18.0-372.87.1.el8_6 | Fixed | RHSA-2024:0412 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-162.6.1.el9_1 | Fixed | RHSA-2022:8267 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-162.6.1.el9_1 | Fixed | RHSA-2022:8267 |
| Red Hat Enterprise Linux 9 | kernel-rt-0:5.14.0-162.6.1.rt21.168.el9_1 | Fixed | RHSA-2022:7933 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 | kernel-0:4.18.0-372.87.1.el8_6 | Fixed | RHSA-2024:0412 |
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Keeping this issue Moderate, because the impact is limited: likely only possibility of memory leak and crash, but not privileges escalation and both kind of race condition that is hard to trigger.
Red Hat mitigation
To mitigate this issue, prevent the module ath9k from being loaded. Please see https://access.redhat.com/solutions/41278 for information on how to blacklist a kernel module to prevent it from loading automatically.
References (10)
- https://access.redhat.com/security/cve/CVE-2022-1679 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2084125 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-24965 Advisory
- https://lists.debian.org/debian-lts-announce/2022/10/msg00000.html mailing-listMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/11/msg00001.html mailing-listMailing ListThird Party Advisory
- https://lore.kernel.org/lkml/87ilqc7jv9.fsf%40kernel.org/t/ PatchThird Party Advisory
- https://lore.kernel.org/lkml/87ilqc7jv9.fsf@kernel.org/t/
- https://nvd.nist.gov/vuln/detail/CVE-2022-1679
- https://security.netapp.com/advisory/ntap-20220629-0007/ Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-1679
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-1679 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2084125 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-24965 | Advisory | |
| https://lists.debian.org/debian-lts-announce/2022/10/msg00000.html | mailing-listMailing ListThird Party Advisory | |
| https://lists.debian.org/debian-lts-announce/2022/11/msg00001.html | mailing-listMailing ListThird Party Advisory | |
| https://lore.kernel.org/lkml/87ilqc7jv9.fsf%40kernel.org/t/ | PatchThird Party Advisory | |
| https://lore.kernel.org/lkml/87ilqc7jv9.fsf@kernel.org/t/ | ||
| https://nvd.nist.gov/vuln/detail/CVE-2022-1679 | ||
| https://security.netapp.com/advisory/ntap-20220629-0007/ | Third Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2022-1679 |
Change history (0)
No recorded changes yet.