cbcvebase.
CVE-2022-49416
published 2025-02-26

CVE-2022-49416: In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix use-after-free in chanctx code In ieee80211_vif_use_reserved_context()…

PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.27%
18.9th percentile
In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix use-after-free in chanctx code In ieee80211_vif_use_reserved_context(), when we have an old context and the new context's replace_state is set to IEEE80211_CHANCTX_REPLACE_NONE, we free the old context in ieee80211_vif_use_reserved_reassign(). Therefore, we cannot check the old_ctx anymore, so we should set it to NULL after this point. However, since the new_ctx replace state is clearly not IEEE80211_CHANCTX_REPLACES_OTHER, we're not going to do anything else in this function and can just return to avoid accessing the freed old_ctx.

Affected

23 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.18.5-1 (bookworm)linux 5.18.5-1 (bookworm)
linuxlinux
linuxlinux>= 5bcae31d9cb1ebfad3ad5a3eea04c8cdc329a04f < 88cc8f963febe192d6ded9df7217f92f380b449a88cc8f963febe192d6ded9df7217f92f380b449a
linuxlinux>= 5bcae31d9cb1ebfad3ad5a3eea04c8cdc329a04f < 4ba81e794f0fad6234f644c2da1ae14d5b95e1c44ba81e794f0fad6234f644c2da1ae14d5b95e1c4
linuxlinux>= 5bcae31d9cb1ebfad3ad5a3eea04c8cdc329a04f < 9f1e5cc85ad77e52f54049a94db0407445ae2a349f1e5cc85ad77e52f54049a94db0407445ae2a34
linuxlinux>= 5bcae31d9cb1ebfad3ad5a3eea04c8cdc329a04f < 265bec4779a38b65e86a25120370f200822dfa76265bec4779a38b65e86a25120370f200822dfa76
linuxlinux>= 5bcae31d9cb1ebfad3ad5a3eea04c8cdc329a04f < 6118bbdf69f4718b02d26bbcf2e497eb660043316118bbdf69f4718b02d26bbcf2e497eb66004331
linuxlinux>= 5bcae31d9cb1ebfad3ad5a3eea04c8cdc329a04f < b79110f2bf6022e60e590d2e094728a8eec3e79eb79110f2bf6022e60e590d2e094728a8eec3e79e
linuxlinux>= 5bcae31d9cb1ebfad3ad5a3eea04c8cdc329a04f < 82c8e7bbdd06c7ed58e22450cc5b37f33a25bb2c82c8e7bbdd06c7ed58e22450cc5b37f33a25bb2c
linuxlinux>= 5bcae31d9cb1ebfad3ad5a3eea04c8cdc329a04f < 4f05a9e15edcdf5b97e0d86ab6ecd5f187289f6c4f05a9e15edcdf5b97e0d86ab6ecd5f187289f6c
linuxlinux>= 5bcae31d9cb1ebfad3ad5a3eea04c8cdc329a04f < 2965c4cdf7ad9ce0796fac5e57debb9519ea721e2965c4cdf7ad9ce0796fac5e57debb9519ea721e
linuxlinux_kernel>= 0 < 5.10.127-15.10.127-1
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 3.17 < 4.9.3184.9.318
linuxlinux_kernel>= 4.10 < 4.14.2834.14.283
linuxlinux_kernel>= 4.15 < 4.19.2474.19.247
linuxlinux_kernel>= 4.20 < 5.4.1985.4.198
linuxlinux_kernel>= 5.11 < 5.15.465.15.46
linuxlinux_kernel>= 5.16 < 5.17.145.17.14
linuxlinux_kernel>= 5.18 < 5.18.35.18.3
linuxlinux_kernel>= 5.5 < 5.10.1215.10.121

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.