Aller au contenu

Fiche vulnérabilité

CVE-2022-49503 : faille élevée linux linux kernel (CVSS 7.1)

Description

In the Linux kernel, the following vulnerability has been resolved: ath9k_htc: fix potential out of bounds access with invalid rxstatus->rs_keyix The "rxstatus->rs_keyix" eventually gets passed to test_bit() so we need to ensure that it is within the bitmap. drivers/net/wireless/ath/ath9k/common.c:46 ath9k_cmn_rx_accept() error: passing untrusted data 'rx_stats->rs_keyix' to 'test_bit()'

En bref

Sévérité
Élevée (CVSS 7.1)
Vecteur CVSS
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Exploitation active
Non signalée par la CISA
Publication
26 févr. 2025
Dernière mise à jour
17 juin 2026

Produits concernés

  • linux linux kernel

Références

Rechercher une autre vulnérabilité dans la base CVE