Researchers disclosed five flaws in the Linux kernel's cfg80211 and mac80211 Wi-Fi stack that can be triggered by malicious wireless frames. CVE-2022-41674, CVE-2022-42719, and CVE-2022-42720 were assessed as potentially permitting remote code execution; CVE-2022-42721 and CVE-2022-42722 can cause denial of service. The latter issues stem from list corruption in cfg80211_add_nontrans_list and erroneous P2P-Device beacon-protection handling in ieee80211_rx_h_decrypt; Red Hat also reports that CVE-2022-41674 can crash affected systems or expose kernel information through an integer overflow in Wi-Fi scan handling.
Red Hat released corrected kernel and kernel-rt packages for affected RHEL 8 and 9 systems, including RHEL 8.6 EUS and Red Hat Virtualization 4 for RHEL 8; RHEL 6 and 7 variants are listed as unaffected. Organizations should prioritize installation of the applicable kernel advisories on systems using Wi-Fi hardware, particularly where attackers can operate within radio range. Where immediate patching is not possible, Red Hat recommends preventing the mac80211 module from loading to mitigate CVE-2022-42722; no qualifying mitigation is available for CVE-2022-41674 or CVE-2022-42721.

See affected versions and whether adversaries are exploiting it.
10 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2023:2736 and RHSA-2023:2951 for affected RHEL 8 kernel and kernel-rt packages, fixing CVE-2022-41674, CVE-2022-42721, and CVE-2022-42722. Red Hat also closed Bug 2134517, its tracking record for CVE-2022-42722.
Red Hat issued RHSA-2023:2148 and RHSA-2023:2458 to fix CVE-2022-41674, CVE-2022-42721, and CVE-2022-42722 in affected RHEL 9 kernel and kernel-rt packages.
Rohit Keshri reported the beacon-protection flaw affecting Wi-Fi P2P Device interfaces, which can dereference a missing netdev pointer and cause a kernel denial of service. Red Hat tracked the issue as Bug 2134517.
SUSE disclosed five Linux WLAN-stack flaws after Soenke Huster and Intel's Johannes Berg investigated an over-the-air mac80211 buffer-overwrite issue. CVE-2022-41674, CVE-2022-42719, and CVE-2022-42720 were assessed as potentially enabling remote code execution, while CVE-2022-42721 and CVE-2022-42722 could cause denial of service; a patch set was submitted for Linux netdev review.
Red Hat closed the tracking bugs for CVE-2020-24587, CVE-2020-24588, and CVE-2020-26139 after recording upstream, Fedora, and RHEL remediation information.
Wade Mealing reported Red Hat bugs for CVE-2020-24587, CVE-2020-24588, and CVE-2020-26139. The flaws respectively involved mixed-key fragment reassembly, Wi-Fi payload parsing as Layer 2 frames, and forwarding EAPOL frames from unauthenticated clients.
Johannes Berg submitted an 18-patch mac80211 and ath10k/ath11k security-fix series addressing Linux cases of 12 Wi-Fi flaws identified by Mathy Vanhoef, including fragment-reassembly, encryption-validation, A-MSDU, and EAPOL-forwarding issues. The affected CVEs included CVE-2020-24586 through CVE-2020-24588 and CVE-2020-26139 through CVE-2020-26147.
RHSA-2024:1188 fixed CVE-2022-41674, CVE-2022-42721, and CVE-2022-42722 for the RHEL 8.6 Extended Update Support kernel and Red Hat Virtualization 4 for RHEL 8.
Fedora shipped fixes in its stable Linux 5.12.9 kernel updates for CVE-2020-24587, CVE-2020-24588, CVE-2020-26139, CVE-2020-26144, and CVE-2020-26146.
Red Hat addressed CVE-2020-24586, CVE-2020-24587, CVE-2020-24588, CVE-2020-26139, CVE-2020-26144, and CVE-2020-26146 for Red Hat Enterprise Linux 8 through RHSA-2021:4140 and RHSA-2021:4356.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
12 references tracked. Mallory keeps watching after this page renders.
redhat.com
Open sourceredhat.com
Open sourceredhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcelore.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.