CVE-2022-1734: Use After Free
A flaw in Linux Kernel found in nfcmrvlnciunregisterdev() in drivers/nfc/nfcmrvl/main.c can lead to use after free both read or write when non synchronized between cleanup routine and firmware download routine.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.262-1Fixed in 6.1.176-1Fixed in 6.1.180-1Fixed in 6.12.94-1Fixed in 6.12.101-1Fixed in 7.1.7-1Fixed in 7.1.8-1
Event History
Frequently Asked Questions
What is the severity of CVE-2022-1734?
CVE-2022-1734 is classified as a medium severity vulnerability due to potential use after free issues.
How do I fix CVE-2022-1734?
To fix CVE-2022-1734, update to the latest kernel versions such as 5.10.223-1, 5.10.226-1, 6.1.123-1, or newer.
Which versions of the Linux Kernel are affected by CVE-2022-1734?
CVE-2022-1734 affects Linux Kernel versions up to 5.18 including specific release candidates.
What systems are vulnerable to CVE-2022-1734?
CVE-2022-1734 primarily affects Linux Kernel users and systems running the specified affected versions on Debian.
Is CVE-2022-1734 exploitable remotely?
CVE-2022-1734 may allow for exploitation in certain circumstances, depending on the system's configuration and use case.