cbcvebase.
CVE-2022-50551
published 2025-10-07

CVE-2022-50551: In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: Fix potential shift-out-of-bounds in brcmf_fw_alloc_request() This patch…

PriorityP431high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.21%
10.7th percentile
In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: Fix potential shift-out-of-bounds in brcmf_fw_alloc_request() This patch fixes a shift-out-of-bounds in brcmfmac that occurs in BIT(chiprev) when a 'chiprev' provided by the device is too large. It should also not be equal to or greater than BITS_PER_TYPE(u32) as we do bitwise AND with a u32 variable and BIT(chiprev). The patch adds a check that makes the function return NULL if that is the case. Note that the NULL case is later handled by the bus-specific caller, brcmf_usb_probe_cb() or brcmf_usb_reset_resume(), for example. Found by a modified version of syzkaller. UBSAN: shift-out-of-bounds in drivers/net/wireless/broadcom/brcm80211/brcmfmac/firmware.c shift exponent 151055786 is too large for 64-bit type 'long unsigned int' CPU: 0 PID: 1885 Comm: kworker/0:2 Tainted: G O 5.14.0+ #132 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.12.1-0-ga5cab58e9a3f-prebuilt.qemu.org 04/01/2014 Workqueue: usb_hub_wq hub_event Call Trace: dump_stack_lvl+0x57/0x7d ubsan_epilogue+0x5/0x40 __ubsan_handle_shift_out_of_bounds.cold+0x53/0xdb ? lock_chain_count+0x20/0x20 brcmf_fw_alloc_request.cold+0x19/0x3ea ? brcmf_fw_get_firmwares+0x250/0x250 ? brcmf_usb_ioctl_resp_wait+0x1a7/0x1f0 brcmf_usb_get_fwname+0x114/0x1a0 ? brcmf_usb_reset_resume+0x120/0x120 ? number+0x6c4/0x9a0 brcmf_c_process_clm_blob+0x168/0x590 ? put_dec+0x90/0x90 ? enable_ptr_key_workfn+0x20/0x20 ? brcmf_common_pd_remove+0x50/0x50 ? rcu_read_lock_sched_held+0xa1/0xd0 brcmf_c_preinit_dcmds+0x673/0xc40 ? brcmf_c_set_joinpref_default+0x100/0x100 ? rcu_read_lock_sched_held+0xa1/0xd0 ? rcu_read_lock_bh_held+0xb0/0xb0 ? lock_acquire+0x19d/0x4e0 ? find_held_lock+0x2d/0x110 ? brcmf_usb_deq+0x1cc/0x260 ? mark_held_locks+0x9f/0xe0 ? lockdep_hardirqs_on_prepare+0x273/0x3e0 ? _raw_spin_unlock_irqrestore+0x47/0x50 ? trace_hardirqs_on+0x1c/0x120 ? brcmf_usb_deq+0x1a7/0x260 ? brcmf_usb_rx_fill_all+0x5a/0xf0 brcmf_attach+0x246/0x

Affected

24 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.4-1 (bookworm)linux 6.1.4-1 (bookworm)
linuxlinux
linuxlinux>= 46d703a775394e4724509ff55cdda41d228c028c < 1db036d13e10809943c2dce553e2fa7fc9c6cd801db036d13e10809943c2dce553e2fa7fc9c6cd80
linuxlinux>= 46d703a775394e4724509ff55cdda41d228c028c < bc45aa1911bf699b9905f12414e3c1879d6b784fbc45aa1911bf699b9905f12414e3c1879d6b784f
linuxlinux>= 46d703a775394e4724509ff55cdda41d228c028c < 4c8fc44c44b97854623c56363c359f711fc0b8874c8fc44c44b97854623c56363c359f711fc0b887
linuxlinux>= 46d703a775394e4724509ff55cdda41d228c028c < 9d2f70fa2c7cc6c73a420ff15682454782d3d6f69d2f70fa2c7cc6c73a420ff15682454782d3d6f6
linuxlinux>= 46d703a775394e4724509ff55cdda41d228c028c < 5b06a8a25eba07628313aa3c5496522eff97be535b06a8a25eba07628313aa3c5496522eff97be53
linuxlinux>= 46d703a775394e4724509ff55cdda41d228c028c < 87792567d9ed93fd336d2c3b8d7870f44e141e6d87792567d9ed93fd336d2c3b8d7870f44e141e6d
linuxlinux>= 46d703a775394e4724509ff55cdda41d228c028c < 0b12d2aa264bac35bff9b5399bb162262b2b89490b12d2aa264bac35bff9b5399bb162262b2b8949
linuxlinux>= 46d703a775394e4724509ff55cdda41d228c028c < 579c9b9838e8a73f6e93ddece07972c241514dcc579c9b9838e8a73f6e93ddece07972c241514dcc
linuxlinux>= 46d703a775394e4724509ff55cdda41d228c028c < ffb589963df103caaf062081a32db0b9e1798660ffb589963df103caaf062081a32db0b9e1798660
linuxlinux>= 46d703a775394e4724509ff55cdda41d228c028c < 81d17f6f3331f03c8eafdacea68ab773426c1e3c81d17f6f3331f03c8eafdacea68ab773426c1e3c
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 4.10 < 4.14.3054.14.305
linuxlinux_kernel>= 4.15 < 4.19.2704.19.270
linuxlinux_kernel>= 4.20 < 5.4.2295.4.229
linuxlinux_kernel>= 4.5 < 4.9.3374.9.337
linuxlinux_kernel>= 5.11 < 5.15.865.15.86
linuxlinux_kernel>= 5.16 < 6.0.166.0.16
linuxlinux_kernel>= 5.5 < 5.10.1635.10.163
linuxlinux_kernel>= 6.1 < 6.1.26.1.2

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.