An issue was discovered in the Linux kernel before 6.0.11. Missing validation of IEEE80211P2PATTRCHANNELLIST in drivers/net/wireless/microchip/wilc1000/cfg80211.c in the WILC1000 wireless driver can trigger a heap-based buffer overflow when parsing the operating channel attribute from Wi-Fi management frames.
[
{
"id": "CVE-2022-47521-7656324b",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"71924105484432676459524527070986276081",
"157121025356034271027226365490146721641",
"164428294128620440543412567984648400857",
"326208543957915610816150188149715519850"
]
},
"deprecated": false,
"source": "https://github.com/torvalds/linux/commit/f9b62f9843c7b0afdaecabbcebf1dbba18599408",
"signature_type": "Line",
"target": {
"file": "drivers/net/wireless/microchip/wilc1000/cfg80211.c"
}
},
{
"id": "CVE-2022-47521-b21f2d53",
"signature_version": "v1",
"digest": {
"function_hash": "202503522673248561636424061794640659796",
"length": 1147.0
},
"deprecated": false,
"source": "https://github.com/torvalds/linux/commit/f9b62f9843c7b0afdaecabbcebf1dbba18599408",
"signature_type": "Function",
"target": {
"file": "drivers/net/wireless/microchip/wilc1000/cfg80211.c",
"function": "wilc_wfi_cfg_parse_ch_attr"
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-47521.json"