CVE-2022-49405

Summary

In the Linux kernel, the following vulnerability has been resolved:

staging: r8188eu: prevent ->Ssid overflow in rtw_wx_set_scan()

This code has a check to prevent read overflow but it needs another check to prevent writing beyond the end of the ->Ssid[] array.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux2b42bd58b32155a1be4dd78991845dec05aaef9e < ac2eab7de458f5e1210ce1237afab40a307075c8affected
LinuxLinux2b42bd58b32155a1be4dd78991845dec05aaef9e < c4bd6b72df4f01aa866ceb298466d6d07a6bd525affected
LinuxLinux2b42bd58b32155a1be4dd78991845dec05aaef9e < 476bfda0be0f9669add92bff604ca78226cf53d1affected
LinuxLinux2b42bd58b32155a1be4dd78991845dec05aaef9e < bc10916e890948d8927a5c8c40fb5dc44be5e1b8affected
LinuxLinux5.15affected
LinuxLinux0 < 5.15unaffected
LinuxLinux5.15.46 <= 5.15.*unaffected
LinuxLinux5.17.14 <= 5.17.*unaffected
LinuxLinux5.18.3 <= 5.18.*unaffected
LinuxLinux5.19 <= *unaffected

Weaknesses

References