CVE-2022-50358
published 2025-09-17CVE-2022-50358: In the Linux kernel, the following vulnerability has been resolved: brcmfmac: return error when getting invalid max_flowrings from dongle When firmware hit…
PriorityP411medium4.2CVSS 3.1
AVPACHPRNUINSUCNINAH
EPSS
0.27%
19.8th percentile
In the Linux kernel, the following vulnerability has been resolved:
brcmfmac: return error when getting invalid max_flowrings from dongle
When firmware hit trap at initialization, host will read abnormal
max_flowrings number from dongle, and it will cause kernel panic when
doing iowrite to initialize dongle ring.
To detect this error at early stage, we directly return error when getting
invalid max_flowrings(>256).
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.4-1 (bookworm) | linux 6.1.4-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 9e37f045d5e7f33450515f237c2f6f6bfee137dd < 3cc9299036bdb647408e11e41de3eb1ff6d428cd | 3cc9299036bdb647408e11e41de3eb1ff6d428cd |
| linux | linux | >= 9e37f045d5e7f33450515f237c2f6f6bfee137dd < 2e8bb402b060a6c22160de3d72cee057698177c8 | 2e8bb402b060a6c22160de3d72cee057698177c8 |
| linux | linux | >= 9e37f045d5e7f33450515f237c2f6f6bfee137dd < 10c4b63d09a5b0ebf1b61af1dae7f25555cf58b6 | 10c4b63d09a5b0ebf1b61af1dae7f25555cf58b6 |
| linux | linux | >= 9e37f045d5e7f33450515f237c2f6f6bfee137dd < 87f126b25fa8562196f0f4c0aa46a446026199bf | 87f126b25fa8562196f0f4c0aa46a446026199bf |
| linux | linux | >= 9e37f045d5e7f33450515f237c2f6f6bfee137dd < 200347eb3b2608cc8b54c13dd1d5e03809ba2eb2 | 200347eb3b2608cc8b54c13dd1d5e03809ba2eb2 |
| linux | linux | >= 9e37f045d5e7f33450515f237c2f6f6bfee137dd < 2aca4f3734bd717e04943ddf340d49ab62299a00 | 2aca4f3734bd717e04943ddf340d49ab62299a00 |
| linux | linux_kernel | < 5.4.229 | 5.4.229 |
| linux | linux_kernel | >= 0 < 5.10.178-1 | 5.10.178-1 |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 5.11 < 5.15.86 | 5.15.86 |
| linux | linux_kernel | >= 5.16 < 6.0.16 | 6.0.16 |
| linux | linux_kernel | >= 5.5 < 5.10.163 | 5.10.163 |
| linux | linux_kernel | >= 6.1 < 6.1.2 | 6.1.2 |
CVSS provenance
nvdv3.14.2MEDIUMCVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
osv4.2MEDIUM
vendor_debian4.2MEDIUM
vendor_redhat4.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: brcmfmac: return error when getting invalid max_flowrings from dongle
vendor_redhat·2025-09-17·CVSS 4.2
CVE-2022-50358 [MEDIUM] CWE-20 kernel: brcmfmac: return error when getting invalid max_flowrings from dongle
kernel: brcmfmac: return error when getting invalid max_flowrings from dongle
In the Linux kernel, the following vulnerability has been resolved:
brcmfmac: return error when getting invalid max_flowrings from dongle
When firmware hit trap at initialization, host will read abnormal
max_flowrings number from dongle, and it will cause kernel panic when
doing iowrite to initialize dongle ring.
To detect this error at early stage, we directly return error when getting
invalid max_flowrings(>256).
Statement: The patch adds input validation for max_flowrings in the brcmfmac PCIe driver to prevent a kernel panic when a trapped/buggy dongle firmware returns an invalid ring count (>256).
This issue requires a malfunctioning or tampered device firmware during initialization and results in availabil
Debian
CVE-2022-50358: linux - In the Linux kernel, the following vulnerability has been resolved: brcmfmac: r...
vendor_debian·2022·CVSS 4.2
CVE-2022-50358 [MEDIUM] CVE-2022-50358: linux - In the Linux kernel, the following vulnerability has been resolved: brcmfmac: r...
In the Linux kernel, the following vulnerability has been resolved: brcmfmac: return error when getting invalid max_flowrings from dongle When firmware hit trap at initialization, host will read abnormal max_flowrings number from dongle, and it will cause kernel panic when doing iowrite to initialize dongle ring. To detect this error at early stage, we directly return error when getting invalid max_flowrings(>256).
Scope: local
bookworm: resolved (fixed in 6.1.4-1)
bullseye: resolved (fixed in 5.10.178-1)
forky: resolved (fixed in 6.1.4-1)
sid: resolved (fixed in 6.1.4-1)
trixie: resolved (fixed in 6.1.4-1)
GHSA
GHSA-pxjm-vgvf-9c27: In the Linux kernel, the following vulnerability has been resolved:
brcmfmac: return error when getting invalid max_flowrings from dongle
When firmw
ghsa_unreviewed·2025-09-17
CVE-2022-50358 [MEDIUM] GHSA-pxjm-vgvf-9c27: In the Linux kernel, the following vulnerability has been resolved:
brcmfmac: return error when getting invalid max_flowrings from dongle
When firmw
In the Linux kernel, the following vulnerability has been resolved:
brcmfmac: return error when getting invalid max_flowrings from dongle
When firmware hit trap at initialization, host will read abnormal
max_flowrings number from dongle, and it will cause kernel panic when
doing iowrite to initialize dongle ring.
To detect this error at early stage, we directly return error when getting
invalid max_flowrings(>256).
OSV
CVE-2022-50358: In the Linux kernel, the following vulnerability has been resolved: brcmfmac: return error when getting invalid max_flowrings from dongle When firmwar
osv·2025-09-17·CVSS 4.2
CVE-2022-50358 [MEDIUM] CVE-2022-50358: In the Linux kernel, the following vulnerability has been resolved: brcmfmac: return error when getting invalid max_flowrings from dongle When firmwar
In the Linux kernel, the following vulnerability has been resolved: brcmfmac: return error when getting invalid max_flowrings from dongle When firmware hit trap at initialization, host will read abnormal max_flowrings number from dongle, and it will cause kernel panic when doing iowrite to initialize dongle ring. To detect this error at early stage, we directly return error when getting invalid max_flowrings(>256).
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/10c4b63d09a5b0ebf1b61af1dae7f25555cf58b6https://git.kernel.org/stable/c/200347eb3b2608cc8b54c13dd1d5e03809ba2eb2https://git.kernel.org/stable/c/2aca4f3734bd717e04943ddf340d49ab62299a00https://git.kernel.org/stable/c/2e8bb402b060a6c22160de3d72cee057698177c8https://git.kernel.org/stable/c/3cc9299036bdb647408e11e41de3eb1ff6d428cdhttps://git.kernel.org/stable/c/87f126b25fa8562196f0f4c0aa46a446026199bf
2025-09-17
Published