CVE-2022-1734
Published on: Not Yet Published
Last Modified on: 10/14/2022 12:42:00 PM UTC
Certain versions of Debian Linux from Debian contain the following vulnerability:
A flaw in Linux Kernel found in nfcmrvl_nci_unregister_dev() in drivers/nfc/nfcmrvl/main.c can lead to use after free both read or write when non synchronized between cleanup routine and firmware download routine.
- CVE-2022-1734 has been assigned by
seca[email protected] to track the vulnerability - currently rated as HIGH severity.
CVSS3 Score: 7 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
LOCAL | HIGH | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVSS2 Score: 4.4 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
LOCAL | MEDIUM | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
PARTIAL | PARTIAL | PARTIAL |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
oss-security - Re: Linux kernel: UAF, null-ptr-deref and double-free vulnerabilities in nfcmrvl module | www.openwall.com text/html |
![]() |
CVE-2022-1734 Linux Kernel Vulnerability in NetApp Products | NetApp Product Security | security.netapp.com text/html |
![]() |
Debian -- Security Information -- DSA-5173-1 linux | www.debian.org Depreciated Link text/html |
![]() |
[SECURITY] [DLA 3065-1] linux security update | lists.debian.org text/html |
![]() |
nfc: nfcmrvl: main: reorder destructive operations in nfcmrvl_nci_unr… · torvalds/linux@d270453 · GitHub | github.com text/html |
![]() |
oss-security - Re: Linux kernel: UAF, null-ptr-deref and double-free vulnerabilities in nfcmrvl module | www.openwall.com text/html |
![]() |
Related QID Numbers
- 179374 Debian Security Update for linux (CVE-2022-1734)
- 180282 Debian Security Update for linux (DLA 3065-1)
- 180605 Debian Security Update for linux (DSA 5173-1)
- 198823 Ubuntu Security Notification for Linux kernel (OEM) Vulnerabilities (USN-5471-1)
- 198861 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-5518-1)
- 198891 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-5560-1)
- 198895 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-5562-1)
- 198897 Ubuntu Security Notification for Linux kernel (Intel IoTG) Vulnerabilities (USN-5564-1)
- 198911 Ubuntu Security Notification for Linux kernel (Azure CVM) Vulnerabilities (USN-5582-1)
- 377117 Alibaba Cloud Linux Security Update for cloud-kernel (ALINUX3-SA-2022:0158)
- 377766 Alibaba Cloud Linux Security Update for cloud-kernel (ALINUX2-SA-2022:0049)
- 377871 Alibaba Cloud Linux Security Update for cloud-kernel (ALINUX2-SA-2023:0001)
- 672017 EulerOS Security Update for kernel (EulerOS-SA-2022-2244)
- 672037 EulerOS Security Update for kernel (EulerOS-SA-2022-2257)
- 752231 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:2082-1)
- 752234 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:2080-1)
- 752237 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:2083-1)
- 752240 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:2103-1)
- 752242 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:2104-1)
- 752250 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:2111-1)
- 752254 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:2116-1)
- 752311 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 41 for SLE 12 SP3) (SUSE-SU-2022:2281-1)
- 752370 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:2520-1)
- 753148 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:2615-1)
- 753153 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 13 for SLE 15 SP3) (SUSE-SU-2022:2239-1)
- 753169 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 26 for SLE 15 SP2) (SUSE-SU-2022:2230-1)
- 753181 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 30 for SLE 15 SP1) (SUSE-SU-2022:2206-1)
- 753243 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 14 for SLE 15 SP3) (SUSE-SU-2022:2216-1)
- 753253 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 15 for SLE 15 SP3) (SUSE-SU-2022:2245-1)
- 753276 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 27 for SLE 15 SP1) (SUSE-SU-2022:2276-1)
- 753309 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 29 for SLE 15) (SUSE-SU-2022:2220-1)
- 753353 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 17 for SLE 15 SP3) (SUSE-SU-2022:2262-1)
- 753491 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 0 for SLE 15 SP4) (SUSE-SU-2022:2854-1)
- 902046 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (9818)
- 902049 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (9816)
- 902196 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (9818-1)
- 902332 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (9816-1)
- 906240 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (9818-2)
- 906331 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (9816-2)
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Operating System | Debian | Debian Linux | 10.0 | All | All | All |
Operating System | Debian | Debian Linux | 9.0 | All | All | All |
Operating System | Linux | Linux Kernel | All | All | All | All |
Operating System | Linux | Linux Kernel | 5.18 | rc1 | All | All |
Operating System | Linux | Linux Kernel | 5.18 | rc2 | All | All |
Operating System | Linux | Linux Kernel | 5.18 | rc3 | All | All |
Operating System | Linux | Linux Kernel | 5.18 | rc4 | All | All |
Operating System | Linux | Linux Kernel | 5.18 | rc5 | All | All |
Hardware
| Netapp | H300e | - | All | All | All |
Operating System | Netapp | H300e Firmware | - | All | All | All |
Hardware
| Netapp | H300s | - | All | All | All |
Operating System | Netapp | H300s Firmware | - | All | All | All |
Hardware
| Netapp | H410c | - | All | All | All |
Operating System | Netapp | H410c Firmware | - | All | All | All |
Hardware
| Netapp | H410s | - | All | All | All |
Operating System | Netapp | H410s Firmware | - | All | All | All |
Hardware
| Netapp | H500e | - | All | All | All |
Operating System | Netapp | H500e Firmware | - | All | All | All |
Hardware
| Netapp | H500s | - | All | All | All |
Operating System | Netapp | H500s Firmware | - | All | All | All |
Hardware
| Netapp | H700e | - | All | All | All |
Operating System | Netapp | H700e Firmware | - | All | All | All |
Hardware
| Netapp | H700s | - | All | All | All |
Operating System | Netapp | H700s Firmware | - | All | All | All |
- cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*:
- cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*:
- cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*:
- cpe:2.3:o:linux:linux_kernel:5.18:rc1:*:*:*:*:*:*:
- cpe:2.3:o:linux:linux_kernel:5.18:rc2:*:*:*:*:*:*:
- cpe:2.3:o:linux:linux_kernel:5.18:rc3:*:*:*:*:*:*:
- cpe:2.3:o:linux:linux_kernel:5.18:rc4:*:*:*:*:*:*:
- cpe:2.3:o:linux:linux_kernel:5.18:rc5:*:*:*:*:*:*:
- cpe:2.3:h:netapp:h300e:-:*:*:*:*:*:*:*:
- cpe:2.3:o:netapp:h300e_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:h:netapp:h300s:-:*:*:*:*:*:*:*:
- cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:h:netapp:h410c:-:*:*:*:*:*:*:*:
- cpe:2.3:o:netapp:h410c_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:h:netapp:h410s:-:*:*:*:*:*:*:*:
- cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:h:netapp:h500e:-:*:*:*:*:*:*:*:
- cpe:2.3:o:netapp:h500e_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:h:netapp:h500s:-:*:*:*:*:*:*:*:
- cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:h:netapp:h700e:-:*:*:*:*:*:*:*:
- cpe:2.3:o:netapp:h700e_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:h:netapp:h700s:-:*:*:*:*:*:*:*:
- cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-1734 : A flaw in #Linux Kernel found in nfcmrvl_nci_unregister_dev in drivers/nfc/nfcmrvl/main.c can lea… twitter.com/i/web/status/1… | 2022-05-18 17:07:22 |
![]() |
CVE-2022-1734 | 2022-05-18 17:38:30 |