CVE-2022-49416
published 2025-02-26CVE-2022-49416: In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix use-after-free in chanctx code In ieee80211_vif_use_reserved_context()…
PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.27%
18.9th percentile
In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: fix use-after-free in chanctx code
In ieee80211_vif_use_reserved_context(), when we have an
old context and the new context's replace_state is set to
IEEE80211_CHANCTX_REPLACE_NONE, we free the old context
in ieee80211_vif_use_reserved_reassign(). Therefore, we
cannot check the old_ctx anymore, so we should set it to
NULL after this point.
However, since the new_ctx replace state is clearly not
IEEE80211_CHANCTX_REPLACES_OTHER, we're not going to do
anything else in this function and can just return to
avoid accessing the freed old_ctx.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.18.5-1 (bookworm) | linux 5.18.5-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 5bcae31d9cb1ebfad3ad5a3eea04c8cdc329a04f < 88cc8f963febe192d6ded9df7217f92f380b449a | 88cc8f963febe192d6ded9df7217f92f380b449a |
| linux | linux | >= 5bcae31d9cb1ebfad3ad5a3eea04c8cdc329a04f < 4ba81e794f0fad6234f644c2da1ae14d5b95e1c4 | 4ba81e794f0fad6234f644c2da1ae14d5b95e1c4 |
| linux | linux | >= 5bcae31d9cb1ebfad3ad5a3eea04c8cdc329a04f < 9f1e5cc85ad77e52f54049a94db0407445ae2a34 | 9f1e5cc85ad77e52f54049a94db0407445ae2a34 |
| linux | linux | >= 5bcae31d9cb1ebfad3ad5a3eea04c8cdc329a04f < 265bec4779a38b65e86a25120370f200822dfa76 | 265bec4779a38b65e86a25120370f200822dfa76 |
| linux | linux | >= 5bcae31d9cb1ebfad3ad5a3eea04c8cdc329a04f < 6118bbdf69f4718b02d26bbcf2e497eb66004331 | 6118bbdf69f4718b02d26bbcf2e497eb66004331 |
| linux | linux | >= 5bcae31d9cb1ebfad3ad5a3eea04c8cdc329a04f < b79110f2bf6022e60e590d2e094728a8eec3e79e | b79110f2bf6022e60e590d2e094728a8eec3e79e |
| linux | linux | >= 5bcae31d9cb1ebfad3ad5a3eea04c8cdc329a04f < 82c8e7bbdd06c7ed58e22450cc5b37f33a25bb2c | 82c8e7bbdd06c7ed58e22450cc5b37f33a25bb2c |
| linux | linux | >= 5bcae31d9cb1ebfad3ad5a3eea04c8cdc329a04f < 4f05a9e15edcdf5b97e0d86ab6ecd5f187289f6c | 4f05a9e15edcdf5b97e0d86ab6ecd5f187289f6c |
| linux | linux | >= 5bcae31d9cb1ebfad3ad5a3eea04c8cdc329a04f < 2965c4cdf7ad9ce0796fac5e57debb9519ea721e | 2965c4cdf7ad9ce0796fac5e57debb9519ea721e |
| linux | linux_kernel | >= 0 < 5.10.127-1 | 5.10.127-1 |
| linux | linux_kernel | >= 0 < 5.18.5-1 | 5.18.5-1 |
| linux | linux_kernel | >= 0 < 5.18.5-1 | 5.18.5-1 |
| linux | linux_kernel | >= 0 < 5.18.5-1 | 5.18.5-1 |
| linux | linux_kernel | >= 3.17 < 4.9.318 | 4.9.318 |
| linux | linux_kernel | >= 4.10 < 4.14.283 | 4.14.283 |
| linux | linux_kernel | >= 4.15 < 4.19.247 | 4.19.247 |
| linux | linux_kernel | >= 4.20 < 5.4.198 | 5.4.198 |
| linux | linux_kernel | >= 5.11 < 5.15.46 | 5.15.46 |
| linux | linux_kernel | >= 5.16 < 5.17.14 | 5.17.14 |
| linux | linux_kernel | >= 5.18 < 5.18.3 | 5.18.3 |
| linux | linux_kernel | >= 5.5 < 5.10.121 | 5.10.121 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qq39-f366-wjqw: In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: fix use-after-free in chanctx code
In ieee80211_vif_use_reserved
ghsa_unreviewed·2025-02-27
CVE-2022-49416 [HIGH] CWE-416 GHSA-qq39-f366-wjqw: In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: fix use-after-free in chanctx code
In ieee80211_vif_use_reserved
In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: fix use-after-free in chanctx code
In ieee80211_vif_use_reserved_context(), when we have an
old context and the new context's replace_state is set to
IEEE80211_CHANCTX_REPLACE_NONE, we free the old context
in ieee80211_vif_use_reserved_reassign(). Therefore, we
cannot check the old_ctx anymore, so we should set it to
NULL after this point.
However, since the new_ctx replace state is clearly not
IEEE80211_CHANCTX_REPLACES_OTHER, we're not going to do
anything else in this function and can just return to
avoid accessing the freed old_ctx.
OSV
CVE-2022-49416: In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix use-after-free in chanctx code In ieee80211_vif_use_reserved_c
osv·2025-02-26·CVSS 7.8
CVE-2022-49416 [HIGH] CVE-2022-49416: In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix use-after-free in chanctx code In ieee80211_vif_use_reserved_c
In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix use-after-free in chanctx code In ieee80211_vif_use_reserved_context(), when we have an old context and the new context's replace_state is set to IEEE80211_CHANCTX_REPLACE_NONE, we free the old context in ieee80211_vif_use_reserved_reassign(). Therefore, we cannot check the old_ctx anymore, so we should set it to NULL after this point. However, since the new_ctx replace state is clearly not IEEE80211_CHANCTX_REPLACES_OTHER, we're not going to do anything else in this function and can just return to avoid accessing the freed old_ctx.
Red Hat
kernel: wifi: mac80211: fix use-after-free in chanctx code
vendor_redhat·2025-02-26·CVSS 7.8
CVE-2022-49416 [HIGH] CWE-416 kernel: wifi: mac80211: fix use-after-free in chanctx code
kernel: wifi: mac80211: fix use-after-free in chanctx code
In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: fix use-after-free in chanctx code
In ieee80211_vif_use_reserved_context(), when we have an
old context and the new context's replace_state is set to
IEEE80211_CHANCTX_REPLACE_NONE, we free the old context
in ieee80211_vif_use_reserved_reassign(). Therefore, we
cannot check the old_ctx anymore, so we should set it to
NULL after this point.
However, since the new_ctx replace state is clearly not
IEEE80211_CHANCTX_REPLACES_OTHER, we're not going to do
anything else in this function and can just return to
avoid accessing the freed old_ctx.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Out
Debian
CVE-2022-49416: linux - In the Linux kernel, the following vulnerability has been resolved: wifi: mac80...
vendor_debian·2022·CVSS 7.8
CVE-2022-49416 [HIGH] CVE-2022-49416: linux - In the Linux kernel, the following vulnerability has been resolved: wifi: mac80...
In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix use-after-free in chanctx code In ieee80211_vif_use_reserved_context(), when we have an old context and the new context's replace_state is set to IEEE80211_CHANCTX_REPLACE_NONE, we free the old context in ieee80211_vif_use_reserved_reassign(). Therefore, we cannot check the old_ctx anymore, so we should set it to NULL after this point. However, since the new_ctx replace state is clearly not IEEE80211_CHANCTX_REPLACES_OTHER, we're not going to do anything else in this function and can just return to avoid accessing the freed old_ctx.
Scope: local
bookworm: resolved (fixed in 5.18.5-1)
bullseye: resolved (fixed in 5.10.127-1)
forky: resolved (fixed in 5.18.5-1)
sid: resolved (fixed in 5.18.5-1)
trixie: re
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://git.kernel.org/stable/c/265bec4779a38b65e86a25120370f200822dfa76https://git.kernel.org/stable/c/2965c4cdf7ad9ce0796fac5e57debb9519ea721ehttps://git.kernel.org/stable/c/4ba81e794f0fad6234f644c2da1ae14d5b95e1c4https://git.kernel.org/stable/c/4f05a9e15edcdf5b97e0d86ab6ecd5f187289f6chttps://git.kernel.org/stable/c/6118bbdf69f4718b02d26bbcf2e497eb66004331https://git.kernel.org/stable/c/82c8e7bbdd06c7ed58e22450cc5b37f33a25bb2chttps://git.kernel.org/stable/c/88cc8f963febe192d6ded9df7217f92f380b449ahttps://git.kernel.org/stable/c/9f1e5cc85ad77e52f54049a94db0407445ae2a34https://git.kernel.org/stable/c/b79110f2bf6022e60e590d2e094728a8eec3e79e
2025-02-26
Published