cbcvebase.
CVE-2022-50179
published 2025-06-18

CVE-2022-50179: In the Linux kernel, the following vulnerability has been resolved: ath9k: fix use-after-free in ath9k_hif_usb_rx_cb Syzbot reported use-after-free Read in…

PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.21%
11.8th percentile
In the Linux kernel, the following vulnerability has been resolved: ath9k: fix use-after-free in ath9k_hif_usb_rx_cb Syzbot reported use-after-free Read in ath9k_hif_usb_rx_cb() [0]. The problem was in incorrect htc_handle->drv_priv initialization. Probable call trace which can trigger use-after-free: ath9k_htc_probe_device() /* htc_handle->drv_priv = priv; */ ath9k_htc_wait_for_target() ... ath9k_hif_usb_rx_cb() ath9k_hif_usb_rx_stream() RX_STAT_INC() drv_priv access In order to not add fancy protection for drv_priv we can move htc_handle->drv_priv initialization at the end of the ath9k_htc_probe_device() and add helper macro to make all *_STAT_* macros NULL safe, since syzbot has reported related NULL deref in that macros [1]

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.0.2-1 (bookworm)linux 6.0.2-1 (bookworm)
linuxlinux
linuxlinux>= fb9987d0f748c983bb795a86f47522313f701a08 < 62bc1ea5c7401d77eaf73d0c6a15f3d2e742856e62bc1ea5c7401d77eaf73d0c6a15f3d2e742856e
linuxlinux>= fb9987d0f748c983bb795a86f47522313f701a08 < ab7a0ddf5f1cdec63cb21840369873806fc36d80ab7a0ddf5f1cdec63cb21840369873806fc36d80
linuxlinux>= fb9987d0f748c983bb795a86f47522313f701a08 < e9e21206b8ea62220b486310c61277e7ebfe7cece9e21206b8ea62220b486310c61277e7ebfe7cec
linuxlinux>= fb9987d0f748c983bb795a86f47522313f701a08 < eccd7c3e2596b574241a7670b5b53f5322f470e5eccd7c3e2596b574241a7670b5b53f5322f470e5
linuxlinux>= fb9987d0f748c983bb795a86f47522313f701a08 < 03ca957c5f7b55660957eda20b5db4110319ac7a03ca957c5f7b55660957eda20b5db4110319ac7a
linuxlinux>= fb9987d0f748c983bb795a86f47522313f701a08 < 6b14ab47937ba441e75e8dbb9fbfc9c55efa41c66b14ab47937ba441e75e8dbb9fbfc9c55efa41c6
linuxlinux>= fb9987d0f748c983bb795a86f47522313f701a08 < b66ebac40f64336ae2d053883bee85261060bd27b66ebac40f64336ae2d053883bee85261060bd27
linuxlinux>= fb9987d0f748c983bb795a86f47522313f701a08 < 0ac4827f78c7ffe8eef074bc010e7e34bc22f5330ac4827f78c7ffe8eef074bc010e7e34bc22f533
linuxlinux_kernel>= 0 < 5.10.140-15.10.140-1
linuxlinux_kernel>= 0 < 6.0.2-16.0.2-1
linuxlinux_kernel>= 0 < 6.0.2-16.0.2-1
linuxlinux_kernel>= 0 < 6.0.2-16.0.2-1
linuxlinux_kernel>= 0 < 4.4.0-276.3104.4.0-276.310
linuxlinux_kernel>= 2.6.35 < 4.14.2914.14.291
linuxlinux_kernel>= 4.15 < 4.19.2564.19.256
linuxlinux_kernel>= 4.20 < 5.4.2115.4.211
linuxlinux_kernel>= 5.11 < 5.15.615.15.61
linuxlinux_kernel>= 5.16 < 5.18.185.18.18
linuxlinux_kernel>= 5.19 < 5.19.25.19.2
linuxlinux_kernel>= 5.5 < 5.10.1375.10.137

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.