Remote kodhi kuuraya kusagadzikana muLinux kernel isina waya stack

Nhepfenyuro yekusagadzikana yakaonekwa mune isina waya stack (mac80211) yeLinux kernel, mamwe ayo anogona kubvumira buffer kufashama uye kure kure kodhi kuuraya nekutumira akagadzirwa mapaketi kubva panzvimbo yekuwana. Iyo gadziriso parizvino inowanikwa chete mune chigamba fomu.

Kuratidza mukana wekuita kurwisa, mienzaniso yemafuremu anokonzeresa kufashukira yakaburitswa, pamwe nerubatsiro rwekutsiva aya mafuremu mu802.11 isina waya stack. Kusagadzikana hakunei nemadhiraivha asina waya anoshandiswa. Zvinofungidzirwa kuti matambudziko akacherechedzwa anogona kushandiswa kugadzira mashandisiro ekushanda kune kure kurwisa masisitimu.

  • CVE-2022-41674 - A buffer kufashukira mu cfg80211_update_notlisted_nontrans basa rinobvumira kusvika ku256 bytes kuti inyorwe pamusoro pemurwi. Kusagadzikana kunoratidzika kutanga neLinux kernel 5.1 uye inogona kushandiswa kure kure kodhi kuuraya.
  • CVE-2022-42719 - Kuwana kune yakatosunungurwa ndangariro nzvimbo (shandisa-mushure-yemahara) muMBSSID parsing kodhi. Kusagadzikana kwave kuoneka kubvira Linux kernel 5.2 uye inogona kushandiswa kure kure kodhi kuuraya.
  • CVE-2022-42720 - Kuwana kune yakatosunungurwa ndangariro (kushandisa-mushure-yemahara) mune referenzi yekuverenga kodhi muBSS (Basic Service Set) modhi. Kusagadzikana kwave kuoneka kubvira Linux kernel 5.1 uye inogona kushandiswa kure kure kodhi kuuraya.
  • CVE-2022-42721 - BSS rondedzero yehuori inotungamira kune isingaperi loop. Kusagadzikana kwave kuoneka kubvira Linux kernel 5.1 uye inogona kushandiswa kukonzera kurambwa kwesevhisi.
  • CVE-2022-42722 - Null pointer dereferences mune beacon furemu yekudzivirira kodhi. Dambudziko rinogona kushandiswa kukonzera kunyimwa basa.

Source: opennet.ru

Voeg