cbcvebase.
CVE-2022-50358
published 2025-09-17

CVE-2022-50358: In the Linux kernel, the following vulnerability has been resolved: brcmfmac: return error when getting invalid max_flowrings from dongle When firmware hit…

PriorityP411medium4.2CVSS 3.1
AVPACHPRNUINSUCNINAH
EPSS
0.27%
19.8th percentile
In the Linux kernel, the following vulnerability has been resolved: brcmfmac: return error when getting invalid max_flowrings from dongle When firmware hit trap at initialization, host will read abnormal max_flowrings number from dongle, and it will cause kernel panic when doing iowrite to initialize dongle ring. To detect this error at early stage, we directly return error when getting invalid max_flowrings(>256).

Affected

17 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.4-1 (bookworm)linux 6.1.4-1 (bookworm)
linuxlinux
linuxlinux>= 9e37f045d5e7f33450515f237c2f6f6bfee137dd < 3cc9299036bdb647408e11e41de3eb1ff6d428cd3cc9299036bdb647408e11e41de3eb1ff6d428cd
linuxlinux>= 9e37f045d5e7f33450515f237c2f6f6bfee137dd < 2e8bb402b060a6c22160de3d72cee057698177c82e8bb402b060a6c22160de3d72cee057698177c8
linuxlinux>= 9e37f045d5e7f33450515f237c2f6f6bfee137dd < 10c4b63d09a5b0ebf1b61af1dae7f25555cf58b610c4b63d09a5b0ebf1b61af1dae7f25555cf58b6
linuxlinux>= 9e37f045d5e7f33450515f237c2f6f6bfee137dd < 87f126b25fa8562196f0f4c0aa46a446026199bf87f126b25fa8562196f0f4c0aa46a446026199bf
linuxlinux>= 9e37f045d5e7f33450515f237c2f6f6bfee137dd < 200347eb3b2608cc8b54c13dd1d5e03809ba2eb2200347eb3b2608cc8b54c13dd1d5e03809ba2eb2
linuxlinux>= 9e37f045d5e7f33450515f237c2f6f6bfee137dd < 2aca4f3734bd717e04943ddf340d49ab62299a002aca4f3734bd717e04943ddf340d49ab62299a00
linuxlinux_kernel< 5.4.2295.4.229
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 5.11 < 5.15.865.15.86
linuxlinux_kernel>= 5.16 < 6.0.166.0.16
linuxlinux_kernel>= 5.5 < 5.10.1635.10.163
linuxlinux_kernel>= 6.1 < 6.1.26.1.2

CVSS provenance

nvdv3.14.2MEDIUMCVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
osv4.2MEDIUM
vendor_debian4.2MEDIUM
vendor_redhat4.2MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.