CVE-2022-50413
published 2025-09-18CVE-2022-50413: In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix use-after-free We've already freed the assoc_data at this point, so…
PriorityP336high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.14%
4.1th percentile
In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: fix use-after-free
We've already freed the assoc_data at this point, so need
to use another copy of the AP (MLD) address instead.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.0.3-1 (bookworm) | linux 6.0.3-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 81151ce462e533551f3284bfdb8e0f461c9220e6 < aebef10affe16228462af680b88751bf137e2856 | aebef10affe16228462af680b88751bf137e2856 |
| linux | linux | >= 81151ce462e533551f3284bfdb8e0f461c9220e6 < 40fb87129049ec5876dabf4a4d4aed6642b31f1a | 40fb87129049ec5876dabf4a4d4aed6642b31f1a |
| linux | linux_kernel | >= 0 < 6.0.3-1 | 6.0.3-1 |
| linux | linux_kernel | >= 0 < 6.0.3-1 | 6.0.3-1 |
| linux | linux_kernel | >= 0 < 6.0.3-1 | 6.0.3-1 |
| linux | linux_kernel | >= 6.0 < 6.0.3 | 6.0.3 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: wifi: mac80211: fix use-after-free
vendor_redhat·2025-09-18·CVSS 7.8
CVE-2022-50413 [HIGH] CWE-416 kernel: wifi: mac80211: fix use-after-free
kernel: wifi: mac80211: fix use-after-free
In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: fix use-after-free
We've already freed the assoc_data at this point, so need
to use another copy of the AP (MLD) address instead.
Statement: A use-after-free in mac80211’s association response handler (MLO path) allowed a malicious or buggy AP to trigger kernel memory corruption on a Wi-Fi client during association. The fix replaces a freed pointer (assoc_data) with a safe copy stored in the vif configuration. Impact is client-side.
For the Red Hat Enterprise Linux both bug and fix introduced starting from 9.2 (so it didn't exist before 9.2 and already fixed starting from 9.2). Similar introduced and fixed simultaneously from 8.8 version of the Red Hat Enterprise
Debian
CVE-2022-50413: linux - In the Linux kernel, the following vulnerability has been resolved: wifi: mac80...
vendor_debian·2022·CVSS 7.8
CVE-2022-50413 [HIGH] CVE-2022-50413: linux - In the Linux kernel, the following vulnerability has been resolved: wifi: mac80...
In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix use-after-free We've already freed the assoc_data at this point, so need to use another copy of the AP (MLD) address instead.
Scope: local
bookworm: resolved (fixed in 6.0.3-1)
bullseye: resolved
forky: resolved (fixed in 6.0.3-1)
sid: resolved (fixed in 6.0.3-1)
trixie: resolved (fixed in 6.0.3-1)
GHSA
GHSA-4j7w-x6gv-jwvh: In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: fix use-after-free
We've already freed the assoc_data at this po
ghsa_unreviewed·2025-09-18
CVE-2022-50413 [HIGH] CWE-416 GHSA-4j7w-x6gv-jwvh: In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: fix use-after-free
We've already freed the assoc_data at this po
In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: fix use-after-free
We've already freed the assoc_data at this point, so need
to use another copy of the AP (MLD) address instead.
OSV
CVE-2022-50413: In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix use-after-free We've already freed the assoc_data at this poin
osv·2025-09-18·CVSS 7.8
CVE-2022-50413 [HIGH] CVE-2022-50413: In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix use-after-free We've already freed the assoc_data at this poin
In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix use-after-free We've already freed the assoc_data at this point, so need to use another copy of the AP (MLD) address instead.
No detection rules found.
No public exploits indexed.
2025-09-18
Published