cbcvebase.
CVE-2022-49740
published 2025-03-27

CVE-2022-49740: In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: Check the count value of channel spec to prevent out-of-bounds reads This…

PriorityP429high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.19%
8.5th percentile
In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: Check the count value of channel spec to prevent out-of-bounds reads This patch fixes slab-out-of-bounds reads in brcmfmac that occur in brcmf_construct_chaninfo() and brcmf_enable_bw40_2g() when the count value of channel specifications provided by the device is greater than the length of 'list->element[]', decided by the size of the 'list' allocated with kzalloc(). The patch adds checks that make the functions free the buffer and return -EINVAL if that is the case. Note that the negative return is handled by the caller, brcmf_setup_wiphybands() or brcmf_cfg80211_attach(). Found by a modified version of syzkaller. Crash Report from brcmf_construct_chaninfo(): BUG: KASAN: slab-out-of-bounds in brcmf_setup_wiphybands+0x1238/0x1430 Read of size 4 at addr ffff888115f24600 by task kworker/0:2/1896 CPU: 0 PID: 1896 Comm: kworker/0:2 Tainted: G W O 5.14.0+ #132 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.12.1-0-ga5cab58e9a3f-prebuilt.qemu.org 04/01/2014 Workqueue: usb_hub_wq hub_event Call Trace: dump_stack_lvl+0x57/0x7d print_address_description.constprop.0.cold+0x93/0x334 kasan_report.cold+0x83/0xdf brcmf_setup_wiphybands+0x1238/0x1430 brcmf_cfg80211_attach+0x2118/0x3fd0 brcmf_attach+0x389/0xd40 brcmf_usb_probe+0x12de/0x1690 usb_probe_interface+0x25f/0x710 really_probe+0x1be/0xa90 __driver_probe_device+0x2ab/0x460 driver_probe_device+0x49/0x120 __device_attach_driver+0x18a/0x250 bus_for_each_drv+0x123/0x1a0 __device_attach+0x207/0x330 bus_probe_device+0x1a2/0x260 device_add+0xa61/0x1ce0 usb_set_configuration+0x984/0x1770 usb_generic_driver_probe+0x69/0x90 usb_probe_device+0x9c/0x220 really_probe+0x1be/0xa90 __driver_probe_device+0x2ab/0x460 driver_probe_device+0x49/0x120 __device_attach_driver+0x18a/0x250 bus_for_each_drv+0x123/0x1a0 __device_attach+0x207/0x330 bus_probe_device+0x1a2/0x260 device_add+0xa61/0x1ce0 usb_new_device.cold+0x463/0xf66 hub_event+0x10d5

Affected

15 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.11-1 (bookworm)linux 6.1.11-1 (bookworm)
linuxlinux
linuxlinux>= d48200ba45dd2edfe6286abfc783a81a4a492e98 < 9cf5e99c1ae1a85286a76c9a970202750538394c9cf5e99c1ae1a85286a76c9a970202750538394c
linuxlinux>= d48200ba45dd2edfe6286abfc783a81a4a492e98 < b2e412879595821ff1b5545cbed5f108fba7f5b6b2e412879595821ff1b5545cbed5f108fba7f5b6
linuxlinux>= d48200ba45dd2edfe6286abfc783a81a4a492e98 < e4991910f15013db72f6ec0db7038ea67a57052ee4991910f15013db72f6ec0db7038ea67a57052e
linuxlinux>= d48200ba45dd2edfe6286abfc783a81a4a492e98 < f06de1bb6d61f0c18b0213bbc6298960037f9d42f06de1bb6d61f0c18b0213bbc6298960037f9d42
linuxlinux>= d48200ba45dd2edfe6286abfc783a81a4a492e98 < 4920ab131b2dbae7464b72bdcac465d0702542094920ab131b2dbae7464b72bdcac465d070254209
linuxlinux_kernel< 5.4.2325.4.232
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.11-16.1.11-1
linuxlinux_kernel>= 0 < 6.1.11-16.1.11-1
linuxlinux_kernel>= 0 < 6.1.11-16.1.11-1
linuxlinux_kernel>= 5.11 < 5.15.935.15.93
linuxlinux_kernel>= 5.16 < 6.1.116.1.11
linuxlinux_kernel>= 5.5 < 5.10.1685.10.168

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.