CVE-2022-26490
Summary
| CVE | CVE-2022-26490 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-03-06 04:15:07 UTC |
| Updated | 2026-09-01 18:04:55 UTC |
| Description | st21nfca_connectivity_event_received in drivers/nfc/st21nfca/se.c in the Linux kernel through 5.16.12 has EVT_TRANSACTION buffer overflows because of untrusted length parameters. |
Risk And Classification
Primary CVSS: v3.1 7.8 HIGH from [email protected]
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Problem Types: CWE-120 | n/a
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 2.0 | [email protected] | Primary | 4.6 | AV:L/AC:L/Au:N/C:P/I:P/A:P |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:L/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Linux | Linux Kernel | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Debian -- Security Information -- DSA-5127-1 linux | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | Third Party Advisory |
| CVE-2022-26490 Linux Kernel Vulnerability in NetApp Products | NetApp Product Security | af854a3a-2127-422b-91ae-364da2661108 | security.netapp.com | Third Party Advisory |
| [SECURITY] Fedora 34 Update: kernel-5.16.15-101.fc34 - package-announce - Fedora Mailing-Lists | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | Third Party Advisory |
| [SECURITY] [DLA 3065-1] linux security update | af854a3a-2127-422b-91ae-364da2661108 | lists.debian.org | Mailing List, Third Party Advisory |
| nfc: st21nfca: Fix potential buffer overflows in EVT_TRANSACTION · torvalds/linux@4fbcc1a · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | Patch, Third Party Advisory |
| [SECURITY] Fedora 35 Update: kernel-5.16.15-201.fc35 - package-announce - Fedora Mailing-Lists | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | Third Party Advisory |
| Debian -- Security Information -- DSA-5173-1 linux | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | Third Party Advisory |
| [SECURITY] Fedora 34 Update: kernel-5.16.15-101.fc34 - package-announce - Fedora Mailing-Lists | MITRE | lists.fedoraproject.org | |
| [SECURITY] Fedora 35 Update: kernel-5.16.15-201.fc35 - package-announce - Fedora Mailing-Lists | MITRE | lists.fedoraproject.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 179258 Debian Security Update for linux (DSA 5127-1)
- 180282 Debian Security Update for linux (DLA 3065-1)
- 180605 Debian Security Update for linux (DSA 5173-1)
- 183107 Debian Security Update for linux (CVE-2022-26490)
- 198747 Ubuntu Security Notification for Linux kernel (OEM) Vulnerabilities (USN-5381-1)
- 198767 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-5390-1)
- 198770 Ubuntu Security Notification for Linux kernel (Raspberry Pi) Vulnerabilities (USN-5390-2)
- 198782 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-5417-1)
- 198784 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-5418-1)
- 198785 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-5415-1)
- 282491 Fedora Security Update for kernel (FEDORA-2022-9342e59a98)
- 282492 Fedora Security Update for kernel (FEDORA-2022-de4474b89d)
- 353215 Amazon Linux Security Advisory for kernel : ALAS-2022-1581
- 353216 Amazon Linux Security Advisory for kernel : ALAS2-2022-1774
- 353237 Amazon Linux Security Advisory for kernel : ALAS2KERNEL-5.4-2022-025
- 353238 Amazon Linux Security Advisory for kernel : ALAS2KERNEL-5.10-2022-013
- 376925 Alibaba Cloud Linux Security Update for cloud-kernel (ALINUX3-SA-2022:0125)
- 377766 Alibaba Cloud Linux Security Update for cloud-kernel (ALINUX2-SA-2022:0049)
- 377871 Alibaba Cloud Linux Security Update for cloud-kernel (ALINUX2-SA-2023:0001)
- 6140124 AWS Bottlerocket Security Update for kernel (GHSA-rvxg-wpjc-3pgf)
- 671734 EulerOS Security Update for kernel (EulerOS-SA-2022-1791)
- 671749 EulerOS Security Update for kernel (EulerOS-SA-2022-1808)
- 671804 EulerOS Security Update for kernel (EulerOS-SA-2022-1844)
- 751952 OpenSUSE Security Update for Linux Kernel (openSUSE-SU-2022:1039-1)
- 751956 OpenSUSE Security Update for the Linux Kernel (openSUSE-SU-2022:1037-1)
- 752016 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:1039-1)
- 752039 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:1196-1)
- 752042 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:1197-1)
- 752048 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:1266-1)
- 752052 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:1255-1)
- 752053 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:1267-1)
- 752056 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:1270-1)
- 752058 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:1256-1)
- 752370 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:2520-1)
- 753148 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:2615-1)
- 753151 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 26 for SLE 15) (SUSE-SU-2022:2709-1)
- 753184 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 11 for SLE 15 SP3) (SUSE-SU-2022:2738-1)
- 753219 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 14 for SLE 15 SP3) (SUSE-SU-2022:2726-1)
- 753246 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 29 for SLE 15 SP1) (SUSE-SU-2022:2728-1)
- 753277 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 28 for SLE 15 SP1) (SUSE-SU-2022:2700-1)
- 753319 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 7 for SLE 15 SP3) (SUSE-SU-2022:2766-1)
- 753346 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 21 for SLE 15 SP2) (SUSE-SU-2022:2783-1)
- 753348 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:1038-1)
- 753373 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:1257-1)
- 753422 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:1037-1)
- 753443 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 24 for SLE 15 SP2) (SUSE-SU-2022:2776-1)
- 753481 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 9 for SLE 15 SP3) (SUSE-SU-2022:2770-1)
- 753491 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 0 for SLE 15 SP4) (SUSE-SU-2022:2854-1)
- 900738 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (8918)
- 901330 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (8918-1)
- 901674 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (8922-1)
- 906084 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (8918-2)
- 906378 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (8922-2)