CVE-2022-28667
Publication date 11 November 2022
Last updated 2 October 2026
Ubuntu priority
Cvss 3 Severity Score
Description
Out-of-bounds write for some Intel(R) PROSet/Wireless WiFi software before version 22.140 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| linux-firmware | 26.04 LTS resolute |
Vulnerable
|
| 24.04 LTS noble |
Vulnerable
|
|
| 22.04 LTS jammy |
Vulnerable
|
|
| 20.04 LTS focal |
Needs evaluation
|
|
| 18.04 LTS bionic |
Needs evaluation
|
|
| 16.04 LTS xenial |
Needs evaluation
|
|
| 14.04 LTS trusty |
Needs evaluation
|
Notes
rodrigo-zaiden
while it is not clear in the advisory, the understanding is that this is a firmware update on the linux-firmware package, which is what being tracked here. I couldn't find which commit on upstream linux-firmware fixes this issue based on the advisory information only.
gianz
the 3168 firmware has not been updated upstream since 2019, so there is no fix for it in any release. resolute: the Intel WiFi firmware ships in the linux-firmware-intel-wireless source.
Patch details
| Package | Patch details |
|---|---|
| linux-firmware |
Severity score breakdown
CVSS version: CVSS v3.0
Base score
6.5 · Medium
Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H