CVE-2022-26966: Medium severity linux kernel vulnerability
An issue was discovered in the Linux kernel before 5.16.12. drivers/net/usb/sr9700.c allows attackers to obtain sensitive information from heap memory via crafted frame lengths from a device.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-26966?
CVE-2022-26966 has been classified with a medium severity level due to its potential to expose sensitive information.
How do I fix CVE-2022-26966?
To mitigate CVE-2022-26966, users should upgrade to the patched versions of the Linux kernel, specifically versions 5.16.12 or higher.
What systems are affected by CVE-2022-26966?
CVE-2022-26966 affects the Linux kernel versions prior to 5.16.12 and certain versions of NetApp Active IQ Unified Manager.
Can CVE-2022-26966 lead to data theft?
Yes, CVE-2022-26966 can allow attackers to gain access to sensitive information from heap memory, posing a risk of data theft.
Is CVE-2022-26966 relevant to all Linux distributions?
CVE-2022-26966 is primarily relevant to distributions using the Linux kernel version before 5.16.12, including certain versions of Debian.