CVE-2022-50258Out-of-bounds Write in Linux

Severity
7.8HIGHNVD
EPSS
0.0%
top 97.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 15

Description

In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: Fix potential stack-out-of-bounds in brcmf_c_preinit_dcmds() This patch fixes a stack-out-of-bounds read in brcmfmac that occurs when 'buf' that is not null-terminated is passed as an argument of strsep() in brcmf_c_preinit_dcmds(). This buffer is filled with a firmware version string by memcpy() in brcmf_fil_iovar_data_get(). The patch ensures buf is null-terminated. Found by a modified version of syzkaller.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages4 packages

NVDlinux/linux_kernel4.154.19.276+6
Debianlinux/linux_kernel< 5.10.178-1+3
CVEListV5linux/linux0af29bf7c1ddf5f3c35577409de46ede5e8d784589243a7b0ea19606ba1c2873c9d569026ccb344f+8
debiandebian/linux< linux 6.1.20-1 (bookworm)

Patches

🔴Vulnerability Details

2
GHSA
GHSA-vcqq-2g47-gfp7: In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: Fix potential stack-out-of-bounds in brcmf_c_preinit_dcmds() Thi2025-09-15
OSV
CVE-2022-50258: In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: Fix potential stack-out-of-bounds in brcmf_c_preinit_dcmds() This2025-09-15

📋Vendor Advisories

2
Red Hat
kernel: wifi: brcmfmac: Fix potential stack-out-of-bounds in brcmf_c_preinit_dcmds()2025-09-15
Debian
CVE-2022-50258: linux - In the Linux kernel, the following vulnerability has been resolved: wifi: brcmf...2022
CVE-2022-50258 — Out-of-bounds Write in Linux | cvebase