yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2022-32293
Component Overview
Vulnerability Overview
Name
CVE-2022-32293
Source
NVD (
link
)
Debian (
link
)
Description
In ConnMan through 1.41, a man-in-the-middle attack against a WISPR HTTP query could be used to trigger a use-after-free in WISPR handling, leading to crashes or code execution.
CWEs
CWE-416
Published Date
Aug 3, 2022
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://bugzilla.suse.com/show_bug.cgi?id=1200190
Issue Tracking
https://lore.kernel.org/connman/20220801080043.4861-1-wagi%40monom.org/
Patch
https://lore.kernel.org/connman/20220801080043.4861-3-wagi%40monom.org/
Patch
https://security.gentoo.org/glsa/202310-21
Third Party Advisory
https://www.debian.org/security/2022/dsa-5231
Third Party Advisory
https://bugzilla.suse.com/show_bug.cgi?id=1200190
Issue Tracking
https://lore.kernel.org/connman/20220801080043.4861-1-wagi%40monom.org/
Patch
https://lore.kernel.org/connman/20220801080043.4861-3-wagi%40monom.org/
Patch
https://security.gentoo.org/glsa/202310-21
Third Party Advisory
https://www.debian.org/security/2022/dsa-5231
Third Party Advisory
Analysis
#
Affected Component
Analysis
connman
Patched
Vulnerability Rating
#
8.1
CVSSv31
Others affected components
#
Name
Project
Project Version
Version
Status
connman
buildroot
2025.02.x
1.45
Not Affected
connman
buildroot
master
2.0
Not Affected
connman
yocto
master
2.0
Not Affected
connman
yocto
scarthgap
1.42
Not Affected
Resolved with patches
#
connman (yocto:kirkstone)
#
Title
Author
Resolve
1
wispr: Add reference counter to portal context
Daniel Wagner <wagi@monom.org>
CVE-2022-32293
2
wispr: Update portal context references
Daniel Wagner <wagi@monom.org>
CVE-2022-32293