Vulnerability Description
drivers/usb/mon/mon_bin.c in usbmon in the Linux kernel before 5.19.15 and 6.x before 6.0.1 allows a user-space client to corrupt the monitor's internal memory.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 2.6.21, < 4.9.331 |
| Debian | Debian Linux | 10.0 |
Related Weaknesses (CWE)
References
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.19.15Release NotesVendor Advisory
- https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.0.1Release NotesVendor Advisory
- https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=a659dPatchVendor Advisory
- https://github.com/torvalds/linux/commit/a659daf63d16aa883be42f3f34ff84235c30219PatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/11/msg00001.htmlMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/12/msg00034.htmlMailing ListThird Party Advisory
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.19.15Release NotesVendor Advisory
- https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.0.1Release NotesVendor Advisory
- https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=a659dPatchVendor Advisory
- https://github.com/torvalds/linux/commit/a659daf63d16aa883be42f3f34ff84235c30219PatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/11/msg00001.htmlMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/12/msg00034.htmlMailing ListThird Party Advisory
FAQ
What is CVE-2022-43750?
CVE-2022-43750 is a vulnerability with a CVSS score of 6.7 (MEDIUM). drivers/usb/mon/mon_bin.c in usbmon in the Linux kernel before 5.19.15 and 6.x before 6.0.1 allows a user-space client to corrupt the monitor's internal memory.
How severe is CVE-2022-43750?
CVE-2022-43750 has been rated MEDIUM with a CVSS base score of 6.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-43750?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Debian Debian Linux.