cbcvebase.
CVE-2022-49503
published 2025-02-26

CVE-2022-49503: In the Linux kernel, the following vulnerability has been resolved: ath9k_htc: fix potential out of bounds access with invalid rxstatus->rs_keyix The…

PriorityP428high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.28%
19.8th percentile
In the Linux kernel, the following vulnerability has been resolved: ath9k_htc: fix potential out of bounds access with invalid rxstatus->rs_keyix The "rxstatus->rs_keyix" eventually gets passed to test_bit() so we need to ensure that it is within the bitmap. drivers/net/wireless/ath/ath9k/common.c:46 ath9k_cmn_rx_accept() error: passing untrusted data 'rx_stats->rs_keyix' to 'test_bit()'

Affected

23 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.18.5-1 (bookworm)linux 5.18.5-1 (bookworm)
linuxlinux
linuxlinux>= 4ed1a8d4a25711f780b96920fff2bb531229e322 < 0bcb528402cd5e1a6e1833e956fd58a12d509e8e0bcb528402cd5e1a6e1833e956fd58a12d509e8e
linuxlinux>= 4ed1a8d4a25711f780b96920fff2bb531229e322 < a048e0c3caa852397b7b50d4c82a0415c05f7ac3a048e0c3caa852397b7b50d4c82a0415c05f7ac3
linuxlinux>= 4ed1a8d4a25711f780b96920fff2bb531229e322 < 4bdcf32c965c27f55ccc4ee71c1927131115b0bb4bdcf32c965c27f55ccc4ee71c1927131115b0bb
linuxlinux>= 4ed1a8d4a25711f780b96920fff2bb531229e322 < 2326d398ccd41ba6d93b8346532dfa432ab00fee2326d398ccd41ba6d93b8346532dfa432ab00fee
linuxlinux>= 4ed1a8d4a25711f780b96920fff2bb531229e322 < 461e4c1f199076275f16bf6f3d3e42c6b6c79f33461e4c1f199076275f16bf6f3d3e42c6b6c79f33
linuxlinux>= 4ed1a8d4a25711f780b96920fff2bb531229e322 < 7f6defe0fabc79f29603c6fa3c80e4fe0456a3e97f6defe0fabc79f29603c6fa3c80e4fe0456a3e9
linuxlinux>= 4ed1a8d4a25711f780b96920fff2bb531229e322 < eda518db7db16c360bc84379d90675650daa3048eda518db7db16c360bc84379d90675650daa3048
linuxlinux>= 4ed1a8d4a25711f780b96920fff2bb531229e322 < 3dad3fed5672828c7fb0465cb66a3d9a70952fa63dad3fed5672828c7fb0465cb66a3d9a70952fa6
linuxlinux>= 4ed1a8d4a25711f780b96920fff2bb531229e322 < 2dc509305cf956381532792cb8dceef2b15047652dc509305cf956381532792cb8dceef2b1504765
linuxlinux_kernel>= 0 < 5.10.127-15.10.127-1
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 0 < 5.18.5-15.18.5-1
linuxlinux_kernel>= 3.15 < 4.9.3184.9.318
linuxlinux_kernel>= 4.10 < 4.14.2834.14.283
linuxlinux_kernel>= 4.15 < 4.19.2474.19.247
linuxlinux_kernel>= 4.20 < 5.4.1985.4.198
linuxlinux_kernel>= 5.11 < 5.15.465.15.46
linuxlinux_kernel>= 5.16 < 5.17.145.17.14
linuxlinux_kernel>= 5.18 < 5.18.35.18.3
linuxlinux_kernel>= 5.5 < 5.10.1215.10.121

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.