First published: Thu Sep 22 2022(Updated: )
An out-of-bounds memory write flaw in the Linux kernel’s USB Monitor component was found in how a user with access to the /dev/usbmon can trigger it by an incorrect write to the memory of the usbmon. This flaw allows a local user to crash or potentially escalate their privileges on the system.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/kernel-rt | <0:3.10.0-1160.90.1.rt56.1235.el7 | 0:3.10.0-1160.90.1.rt56.1235.el7 |
redhat/kernel | <0:3.10.0-1160.90.1.el7 | 0:3.10.0-1160.90.1.el7 |
redhat/kernel-rt | <0:4.18.0-477.10.1.rt7.274.el8_8 | 0:4.18.0-477.10.1.rt7.274.el8_8 |
redhat/kernel | <0:4.18.0-477.10.1.el8_8 | 0:4.18.0-477.10.1.el8_8 |
redhat/kernel | <0:5.14.0-284.11.1.el9_2 | 0:5.14.0-284.11.1.el9_2 |
redhat/kernel-rt | <0:5.14.0-284.11.1.rt14.296.el9_2 | 0:5.14.0-284.11.1.rt14.296.el9_2 |
Linux kernel | >=2.6.21<4.9.331 | |
Linux kernel | >=4.10<4.14.296 | |
Linux kernel | >=4.15<4.19.262 | |
Linux kernel | >=4.20<5.4.218 | |
Linux kernel | >=5.5<5.10.148 | |
Linux kernel | >=5.11<5.15.73 | |
Linux kernel | >=5.16<5.19.15 | |
Linux kernel | >=6.0<6.0.1 | |
Debian | =10.0 | |
F5 BIG-IP and BIG-IQ Centralized Management | >=17.1.0<=17.1.1 | |
F5 BIG-IP and BIG-IQ Centralized Management | >=16.1.0<=16.1.4 | |
F5 BIG-IP and BIG-IQ Centralized Management | >=15.1.0<=15.1.10 | |
F5 BIG-IP and BIG-IQ Centralized Management | >=8.1.0<=8.3.0 | |
F5 F5OS | =1.7.0>=1.5.1<=1.5.2 | |
F5 F5OS | >=1.6.0<=1.6.2 | |
debian/linux | 5.10.223-1 5.10.234-1 6.1.123-1 6.1.128-1 6.12.12-1 6.12.17-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2022-43750 is classified as a high severity vulnerability due to its potential to allow privilege escalation or system crashes.
To fix CVE-2022-43750, ensure you update the Linux kernel to the recommended patched versions provided by your distribution.
CVE-2022-43750 affects local users with access to the /dev/usbmon on vulnerable versions of the Linux kernel and specific F5 BIG-IP products.
CVE-2022-43750 impacts various Linux kernel versions, specifically between 2.6.21 and 6.0.1, along with certain F5 BIG-IP and BIG-IQ Centralized Management versions.
No, CVE-2022-43750 requires local access to exploit, making it a local privilege escalation vulnerability.