#VU104859 Improper Initialization in Linux kernel - CVE-2022-49326


Vulnerability identifier: #VU104859

Vulnerability risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2022-49326

CWE-ID: CWE-665

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
Linux kernel
Operating systems & Components / Operating system

Vendor: Linux Foundation

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to improper initialization within the rtl8180_tx() function in drivers/net/wireless/realtek/rtl818x/rtl8180/dev.c. A local user can perform a denial of service (DoS) attack.

Mitigation
Install update from vendor's website.

Vulnerable software versions

Linux kernel: All versions


External links
https://git.kernel.org/stable/c/6ad81ad0cf5744738ce94c8e64051ddd80a1734c
https://git.kernel.org/stable/c/746285cf81dc19502ab238249d75f5990bd2d231
https://git.kernel.org/stable/c/769ec2a824deae2f1268dfda14999a4d14d0d0c5
https://git.kernel.org/stable/c/98e55b0b876bde3353f4e074883d66ecb55c65a3
https://git.kernel.org/stable/c/9ad1981fc4de3afb7db3e8eb5a6a52d4c7d0d577
https://git.kernel.org/stable/c/9d5e96cc1f1720019ce27b127a31695148d38bb0
https://git.kernel.org/stable/c/b5dca2cd3f0239512da808598b4e70557eb4c2a1
https://git.kernel.org/stable/c/b8ce58ab80faaea015c206382041ff3bcf5495ff
https://git.kernel.org/stable/c/d7e30dfc166d33470bba31a42f9bbc346e5409d5


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability