CVE-2022-49503
published 2025-02-26CVE-2022-49503: In the Linux kernel, the following vulnerability has been resolved: ath9k_htc: fix potential out of bounds access with invalid rxstatus->rs_keyix The…
PriorityP428high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.28%
19.8th percentile
In the Linux kernel, the following vulnerability has been resolved:
ath9k_htc: fix potential out of bounds access with invalid rxstatus->rs_keyix
The "rxstatus->rs_keyix" eventually gets passed to test_bit() so we need to
ensure that it is within the bitmap.
drivers/net/wireless/ath/ath9k/common.c:46 ath9k_cmn_rx_accept()
error: passing untrusted data 'rx_stats->rs_keyix' to 'test_bit()'
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.18.5-1 (bookworm) | linux 5.18.5-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 4ed1a8d4a25711f780b96920fff2bb531229e322 < 0bcb528402cd5e1a6e1833e956fd58a12d509e8e | 0bcb528402cd5e1a6e1833e956fd58a12d509e8e |
| linux | linux | >= 4ed1a8d4a25711f780b96920fff2bb531229e322 < a048e0c3caa852397b7b50d4c82a0415c05f7ac3 | a048e0c3caa852397b7b50d4c82a0415c05f7ac3 |
| linux | linux | >= 4ed1a8d4a25711f780b96920fff2bb531229e322 < 4bdcf32c965c27f55ccc4ee71c1927131115b0bb | 4bdcf32c965c27f55ccc4ee71c1927131115b0bb |
| linux | linux | >= 4ed1a8d4a25711f780b96920fff2bb531229e322 < 2326d398ccd41ba6d93b8346532dfa432ab00fee | 2326d398ccd41ba6d93b8346532dfa432ab00fee |
| linux | linux | >= 4ed1a8d4a25711f780b96920fff2bb531229e322 < 461e4c1f199076275f16bf6f3d3e42c6b6c79f33 | 461e4c1f199076275f16bf6f3d3e42c6b6c79f33 |
| linux | linux | >= 4ed1a8d4a25711f780b96920fff2bb531229e322 < 7f6defe0fabc79f29603c6fa3c80e4fe0456a3e9 | 7f6defe0fabc79f29603c6fa3c80e4fe0456a3e9 |
| linux | linux | >= 4ed1a8d4a25711f780b96920fff2bb531229e322 < eda518db7db16c360bc84379d90675650daa3048 | eda518db7db16c360bc84379d90675650daa3048 |
| linux | linux | >= 4ed1a8d4a25711f780b96920fff2bb531229e322 < 3dad3fed5672828c7fb0465cb66a3d9a70952fa6 | 3dad3fed5672828c7fb0465cb66a3d9a70952fa6 |
| linux | linux | >= 4ed1a8d4a25711f780b96920fff2bb531229e322 < 2dc509305cf956381532792cb8dceef2b1504765 | 2dc509305cf956381532792cb8dceef2b1504765 |
| linux | linux_kernel | >= 0 < 5.10.127-1 | 5.10.127-1 |
| linux | linux_kernel | >= 0 < 5.18.5-1 | 5.18.5-1 |
| linux | linux_kernel | >= 0 < 5.18.5-1 | 5.18.5-1 |
| linux | linux_kernel | >= 0 < 5.18.5-1 | 5.18.5-1 |
| linux | linux_kernel | >= 3.15 < 4.9.318 | 4.9.318 |
| linux | linux_kernel | >= 4.10 < 4.14.283 | 4.14.283 |
| linux | linux_kernel | >= 4.15 < 4.19.247 | 4.19.247 |
| linux | linux_kernel | >= 4.20 < 5.4.198 | 5.4.198 |
| linux | linux_kernel | >= 5.11 < 5.15.46 | 5.15.46 |
| linux | linux_kernel | >= 5.16 < 5.17.14 | 5.17.14 |
| linux | linux_kernel | >= 5.18 < 5.18.3 | 5.18.3 |
| linux | linux_kernel | >= 5.5 < 5.10.121 | 5.10.121 |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w72r-9wq7-mqwh: In the Linux kernel, the following vulnerability has been resolved:
ath9k_htc: fix potential out of bounds access with invalid rxstatus->rs_keyix
Th
ghsa_unreviewed·2025-10-21
CVE-2022-49503 [HIGH] CWE-125 GHSA-w72r-9wq7-mqwh: In the Linux kernel, the following vulnerability has been resolved:
ath9k_htc: fix potential out of bounds access with invalid rxstatus->rs_keyix
Th
In the Linux kernel, the following vulnerability has been resolved:
ath9k_htc: fix potential out of bounds access with invalid rxstatus->rs_keyix
The "rxstatus->rs_keyix" eventually gets passed to test_bit() so we need to
ensure that it is within the bitmap.
drivers/net/wireless/ath/ath9k/common.c:46 ath9k_cmn_rx_accept()
error: passing untrusted data 'rx_stats->rs_keyix' to 'test_bit()'
OSV
CVE-2022-49503: In the Linux kernel, the following vulnerability has been resolved: ath9k_htc: fix potential out of bounds access with invalid rxstatus->rs_keyix The
osv·2025-02-26·CVSS 7.1
CVE-2022-49503 [HIGH] CVE-2022-49503: In the Linux kernel, the following vulnerability has been resolved: ath9k_htc: fix potential out of bounds access with invalid rxstatus->rs_keyix The
In the Linux kernel, the following vulnerability has been resolved: ath9k_htc: fix potential out of bounds access with invalid rxstatus->rs_keyix The "rxstatus->rs_keyix" eventually gets passed to test_bit() so we need to ensure that it is within the bitmap. drivers/net/wireless/ath/ath9k/common.c:46 ath9k_cmn_rx_accept() error: passing untrusted data 'rx_stats->rs_keyix' to 'test_bit()'
Red Hat
kernel: Linux kernel: ath9k_htc out-of-bounds access vulnerability
vendor_redhat·2025-02-26·CVSS 7.1
CVE-2022-49503 [HIGH] CWE-125 kernel: Linux kernel: ath9k_htc out-of-bounds access vulnerability
kernel: Linux kernel: ath9k_htc out-of-bounds access vulnerability
In the Linux kernel, the following vulnerability has been resolved:
ath9k_htc: fix potential out of bounds access with invalid rxstatus->rs_keyix
The "rxstatus->rs_keyix" eventually gets passed to test_bit() so we need to
ensure that it is within the bitmap.
drivers/net/wireless/ath/ath9k/common.c:46 ath9k_cmn_rx_accept()
error: passing untrusted data 'rx_stats->rs_keyix' to 'test_bit()'
A flaw was found in the Linux kernel's ath9k_htc component. This vulnerability allows a local attacker to cause a denial of service or potentially disclose sensitive information via passing untrusted data to `test_bit()`.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Out of s
Debian
CVE-2022-49503: linux - In the Linux kernel, the following vulnerability has been resolved: ath9k_htc: ...
vendor_debian·2022·CVSS 7.1
CVE-2022-49503 [HIGH] CVE-2022-49503: linux - In the Linux kernel, the following vulnerability has been resolved: ath9k_htc: ...
In the Linux kernel, the following vulnerability has been resolved: ath9k_htc: fix potential out of bounds access with invalid rxstatus->rs_keyix The "rxstatus->rs_keyix" eventually gets passed to test_bit() so we need to ensure that it is within the bitmap. drivers/net/wireless/ath/ath9k/common.c:46 ath9k_cmn_rx_accept() error: passing untrusted data 'rx_stats->rs_keyix' to 'test_bit()'
Scope: local
bookworm: resolved (fixed in 5.18.5-1)
bullseye: resolved (fixed in 5.10.127-1)
forky: resolved (fixed in 5.18.5-1)
sid: resolved (fixed in 5.18.5-1)
trixie: resolved (fixed in 5.18.5-1)
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/0bcb528402cd5e1a6e1833e956fd58a12d509e8ehttps://git.kernel.org/stable/c/2326d398ccd41ba6d93b8346532dfa432ab00feehttps://git.kernel.org/stable/c/2dc509305cf956381532792cb8dceef2b1504765https://git.kernel.org/stable/c/3dad3fed5672828c7fb0465cb66a3d9a70952fa6https://git.kernel.org/stable/c/461e4c1f199076275f16bf6f3d3e42c6b6c79f33https://git.kernel.org/stable/c/4bdcf32c965c27f55ccc4ee71c1927131115b0bbhttps://git.kernel.org/stable/c/7f6defe0fabc79f29603c6fa3c80e4fe0456a3e9https://git.kernel.org/stable/c/a048e0c3caa852397b7b50d4c82a0415c05f7ac3https://git.kernel.org/stable/c/eda518db7db16c360bc84379d90675650daa3048
2025-02-26
Published