CVE-2022-47521: Debian Linux

High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.

An issue was discovered in the Linux kernel before 6.0.11. Missing validation of IEEE80211_P2P_ATTR_CHANNEL_LIST in drivers/net/wireless/microchip/wilc1000/cfg80211.c in the WILC1000 wireless driver can trigger a heap-based buffer overflow when parsing the operating channel attribute from Wi-Fi management frames.

Affected products

  • Debian Debian Linux: version 10.0 only
  • Linux Linux Kernel: from 5.7, before 5.10.157 (fixed in 5.10.157); from 5.11, before 5.15.81 (fixed in 5.15.81); from 5.16, before 6.0.11 (fixed in 6.0.11)
  • Netapp h300s Firmware: affected versions not specified
  • Netapp h410c Firmware: affected versions not specified
  • Netapp h410s Firmware: affected versions not specified
  • Netapp h500s Firmware: affected versions not specified
  • Netapp h700s Firmware: affected versions not specified

Published 2022-12-18. Last modified 2026-06-17.