CVE-2022-42719

critical
Published — · Modified —
CVSS v3
CVSS v2
VIR risk
9.5

Description

A use-after-free in the mac80211 stack when parsing a multi-BSSID element in the Linux kernel 5.2 through 5.19.x before 5.19.16 could be used by attackers (able to inject WLAN frames) to crash the kernel and potentially execute code.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2022-42719

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2022-42719.html

vendor Authored 2026-05-27

Vendor advisory: arch — https://security.archlinux.org/ASA-202210-2

vendor Authored 2026-05-27

Vendor advisory: arch — https://security.archlinux.org/ASA-202210-3

vendor Authored 2026-05-27

Vendor advisory: arch — https://security.archlinux.org/ASA-202210-4

vendor Authored 2026-05-27

Vendor advisory: arch — https://security.archlinux.org/ASA-202210-1

OS impact

OSVersionStatusFixed in
arch archfixed5.19.15.hardened2-1
suse slesaffected
debian debianbookwormfixed6.0.2-1
debian debianbullseyefixed5.10.149-1
debian debianforkyfixed6.0.2-1
debian debiansidfixed6.0.2-1
debian debiantrixiefixed6.0.2-1

References

Verify integrity in audit chain (admin only). AS-IS.