7.0highHigh

CVE-2022-1734

Linux Linux Kernel

A flaw in Linux Kernel found in nfcmrvl_nci_unregister_dev() in drivers/nfc/nfcmrvl/main.c can lead to use after free both read or write when non synchronized between cleanup routine and firmware download routine.

Exploitation status

  • Published references include exploit or proof-of-concept material. There is no confirmation it is being used in real attacks.
  • A vendor advisory or patch reference has been published.

What the metrics mean

  • It is requires local access to the machine.
  • For an attacker who can reach it, exploitation depends on conditions outside the attacker's control.
  • To exploit it, an ordinary user account is needed.
  • Beyond that, no action by a user is required.

Scoring

CVSS
7.0 (v3.1)
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness
CWE-416
Assigned by
secalert@redhat.com

Dates

Published
2022-05-18
Last modified
2026-08-26
Sources
NVD

Affected products

  • Linux Linux Kernel4.4 - 4.9.313, 4.10 - 4.14.278, 4.15 - 4.19.242, 4.20 - 5.4.193, 5.5 - 5.10.115, 5.11 - 5.15.39, 5.16 - 5.17.7, 5.18
  • Debian Debian Linux9.0, 10.0
  • Netapp H300s Firmwareall versions
  • Netapp H300sall versions
  • Netapp H500s Firmwareall versions
  • Netapp H500sall versions
  • Netapp H700s Firmwareall versions
  • Netapp H700sall versions
  • Netapp H300e Firmwareall versions
  • Netapp H300eall versions
  • Netapp H500e Firmwareall versions
  • Netapp H500eall versions

As listed in the NVD configuration data. Not a statement about your estate.

References