VDB
SUSE-SU-2022%3A3605-1
SUSE-SU-2022%3A3605-1
PUBLISHED
CVSS 9.300000190734863 CRITICAL
This update for the Linux Kernel 5.14.21-150400_24_18 fixes several issues. The following security issues were fixed: - CVE-2022-41674: Fixed buffer overflow that can be triggered by injected WLAN frames (bsc#1203994). - CVE-2022-42719: Fixed use-after-free in the mac80211 stack when parsing a multi-BSSID element (bsc#1204292). - CVE-2022-42720: Fixed refcounting bugs in the multi-BSS handling of the mac80211 stack (bsc#1204291). - CVE-2022-42721: Fixed list management bug in BSS handling of the mac80211 stack (bsc#1204290). - CVE-2022-39189: Fixed mishandled TLB flush operation in certain KVM_VCPU_PREEMPTED situations (bsc#1203067).
Risk Scores
CVSS 4.0
9.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| SUSE:Linux Enterprise Live Patching 15 SP4 | kernel-livepatch-SLE15-SP4_Update_2 | 0, 0 |
Timeline
- Oct 17, 2022 CVE Published
- Feb 4, 2026 CVE Updated
References
- https://www.suse.com/support/update/announcement/2022/suse-su-20223605-1/ advisory
- https://bugzilla.suse.com/1203067 report
- https://bugzilla.suse.com/1203994 report
- https://bugzilla.suse.com/1204290 report
- https://bugzilla.suse.com/1204291 report
- https://bugzilla.suse.com/1204292 report
- https://www.suse.com/security/cve/CVE-2022-39189 url
- https://www.suse.com/security/cve/CVE-2022-41674 url
- https://www.suse.com/security/cve/CVE-2022-42719 url
- https://www.suse.com/security/cve/CVE-2022-42720 url
- https://www.suse.com/security/cve/CVE-2022-42721 url