Skip to content

kernel CVE-2022-1679

Moderate
rpkelly published GHSA-f9qf-mpgx-j9vf Jan 27, 2023

Package

kernel-5.10 (bottlerocket)

Affected versions

< 1.12.0

Patched versions

1.12.0
kernel-5.15 (bottlerocket)
< 1.12.0
1.12.0

Description

A use-after-free flaw was found in the Linux kernel's Atheros wireless adapter driver in the way a user forces the ath9k_htc_wait_for_target function to fail with some input messages. This flaw allows a local user to crash or potentially escalate their privileges on the system.

Severity

Moderate

CVE ID

CVE-2022-1679

Weaknesses

No CWEs