7.8
CVE-2022-26490
- EPSS 0.43%
- Veröffentlicht 06.03.2022 04:15:07
- Zuletzt bearbeitet 01.09.2026 18:04:55
- Erkennungen
st21nfca_connectivity_event_received in drivers/nfc/st21nfca/se.c in the Linux kernel through 5.16.12 has EVT_TRANSACTION buffer overflows because of untrusted length parameters.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version < 4.9.309
Linux ≫ Linux Kernel Version >= 4.10 < 4.14.274
Linux ≫ Linux Kernel Version >= 4.15 < 4.19.237
Linux ≫ Linux Kernel Version >= 4.20 < 5.4.188
Linux ≫ Linux Kernel Version >= 5.5 < 5.10.109
Linux ≫ Linux Kernel Version >= 5.11 < 5.15.32
Linux ≫ Linux Kernel Version >= 5.16 < 5.16.18
Fedoraproject ≫ Fedora Version 34
Fedoraproject ≫ Fedora Version 35
Netapp ≫ H300s Firmware Version -
Netapp ≫ H500s Firmware Version -
Netapp ≫ H700s Firmware Version -
Netapp ≫ H300e Firmware Version -
Netapp ≫ H500e Firmware Version -
Netapp ≫ H700e Firmware Version -
Netapp ≫ H410s Firmware Version -
Netapp ≫ H410c Firmware Version -
Debian ≫ Debian Linux Version 9.0
Debian ≫ Debian Linux Version 10.0
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.43% | 0.344 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 4.6 | 3.9 | 6.4 |
AV:L/AC:L/Au:N/C:P/I:P/A:P
|
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.
https://lists.debian.org/debian-lts-announce/2022/07/msg00000.html
https://github.com/torvalds/linux/commit/4fbcc1a4cb20fe26ad0225679c536c80f1648221
https://security.netapp.com/advisory/ntap-20220429-0004/
https://www.debian.org/security/2022/dsa-5127
https://www.debian.org/security/2022/dsa-5173
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BG4J46EMFPDD5QHYXDUI3PJCZQ7HQAZR/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/C5AUUDGSDLGYU7SZSK4PFAN22NISQZBT/