CVE-2022-50551
published 2025-10-07CVE-2022-50551: In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: Fix potential shift-out-of-bounds in brcmf_fw_alloc_request() This patch…
PriorityP431high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.21%
10.7th percentile
In the Linux kernel, the following vulnerability has been resolved:
wifi: brcmfmac: Fix potential shift-out-of-bounds in brcmf_fw_alloc_request()
This patch fixes a shift-out-of-bounds in brcmfmac that occurs in
BIT(chiprev) when a 'chiprev' provided by the device is too large.
It should also not be equal to or greater than BITS_PER_TYPE(u32)
as we do bitwise AND with a u32 variable and BIT(chiprev). The patch
adds a check that makes the function return NULL if that is the case.
Note that the NULL case is later handled by the bus-specific caller,
brcmf_usb_probe_cb() or brcmf_usb_reset_resume(), for example.
Found by a modified version of syzkaller.
UBSAN: shift-out-of-bounds in drivers/net/wireless/broadcom/brcm80211/brcmfmac/firmware.c
shift exponent 151055786 is too large for 64-bit type 'long unsigned int'
CPU: 0 PID: 1885 Comm: kworker/0:2 Tainted: G O 5.14.0+ #132
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.12.1-0-ga5cab58e9a3f-prebuilt.qemu.org 04/01/2014
Workqueue: usb_hub_wq hub_event
Call Trace:
dump_stack_lvl+0x57/0x7d
ubsan_epilogue+0x5/0x40
__ubsan_handle_shift_out_of_bounds.cold+0x53/0xdb
? lock_chain_count+0x20/0x20
brcmf_fw_alloc_request.cold+0x19/0x3ea
? brcmf_fw_get_firmwares+0x250/0x250
? brcmf_usb_ioctl_resp_wait+0x1a7/0x1f0
brcmf_usb_get_fwname+0x114/0x1a0
? brcmf_usb_reset_resume+0x120/0x120
? number+0x6c4/0x9a0
brcmf_c_process_clm_blob+0x168/0x590
? put_dec+0x90/0x90
? enable_ptr_key_workfn+0x20/0x20
? brcmf_common_pd_remove+0x50/0x50
? rcu_read_lock_sched_held+0xa1/0xd0
brcmf_c_preinit_dcmds+0x673/0xc40
? brcmf_c_set_joinpref_default+0x100/0x100
? rcu_read_lock_sched_held+0xa1/0xd0
? rcu_read_lock_bh_held+0xb0/0xb0
? lock_acquire+0x19d/0x4e0
? find_held_lock+0x2d/0x110
? brcmf_usb_deq+0x1cc/0x260
? mark_held_locks+0x9f/0xe0
? lockdep_hardirqs_on_prepare+0x273/0x3e0
? _raw_spin_unlock_irqrestore+0x47/0x50
? trace_hardirqs_on+0x1c/0x120
? brcmf_usb_deq+0x1a7/0x260
? brcmf_usb_rx_fill_all+0x5a/0xf0
brcmf_attach+0x246/0x
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.4-1 (bookworm) | linux 6.1.4-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 46d703a775394e4724509ff55cdda41d228c028c < 1db036d13e10809943c2dce553e2fa7fc9c6cd80 | 1db036d13e10809943c2dce553e2fa7fc9c6cd80 |
| linux | linux | >= 46d703a775394e4724509ff55cdda41d228c028c < bc45aa1911bf699b9905f12414e3c1879d6b784f | bc45aa1911bf699b9905f12414e3c1879d6b784f |
| linux | linux | >= 46d703a775394e4724509ff55cdda41d228c028c < 4c8fc44c44b97854623c56363c359f711fc0b887 | 4c8fc44c44b97854623c56363c359f711fc0b887 |
| linux | linux | >= 46d703a775394e4724509ff55cdda41d228c028c < 9d2f70fa2c7cc6c73a420ff15682454782d3d6f6 | 9d2f70fa2c7cc6c73a420ff15682454782d3d6f6 |
| linux | linux | >= 46d703a775394e4724509ff55cdda41d228c028c < 5b06a8a25eba07628313aa3c5496522eff97be53 | 5b06a8a25eba07628313aa3c5496522eff97be53 |
| linux | linux | >= 46d703a775394e4724509ff55cdda41d228c028c < 87792567d9ed93fd336d2c3b8d7870f44e141e6d | 87792567d9ed93fd336d2c3b8d7870f44e141e6d |
| linux | linux | >= 46d703a775394e4724509ff55cdda41d228c028c < 0b12d2aa264bac35bff9b5399bb162262b2b8949 | 0b12d2aa264bac35bff9b5399bb162262b2b8949 |
| linux | linux | >= 46d703a775394e4724509ff55cdda41d228c028c < 579c9b9838e8a73f6e93ddece07972c241514dcc | 579c9b9838e8a73f6e93ddece07972c241514dcc |
| linux | linux | >= 46d703a775394e4724509ff55cdda41d228c028c < ffb589963df103caaf062081a32db0b9e1798660 | ffb589963df103caaf062081a32db0b9e1798660 |
| linux | linux | >= 46d703a775394e4724509ff55cdda41d228c028c < 81d17f6f3331f03c8eafdacea68ab773426c1e3c | 81d17f6f3331f03c8eafdacea68ab773426c1e3c |
| linux | linux_kernel | >= 0 < 5.10.178-1 | 5.10.178-1 |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 4.10 < 4.14.305 | 4.14.305 |
| linux | linux_kernel | >= 4.15 < 4.19.270 | 4.19.270 |
| linux | linux_kernel | >= 4.20 < 5.4.229 | 5.4.229 |
| linux | linux_kernel | >= 4.5 < 4.9.337 | 4.9.337 |
| linux | linux_kernel | >= 5.11 < 5.15.86 | 5.15.86 |
| linux | linux_kernel | >= 5.16 < 6.0.16 | 6.0.16 |
| linux | linux_kernel | >= 5.5 < 5.10.163 | 5.10.163 |
| linux | linux_kernel | >= 6.1 < 6.1.2 | 6.1.2 |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Linux Kernel up to 6.1.1 firmware.c brcmf_fw_alloc_request out-of-bounds (EUVD-2025-32015 / Nessus ID 279908)
vuldb·2026-04-20·CVSS 7.1
CVE-2022-50551 [HIGH] Linux Kernel up to 6.1.1 firmware.c brcmf_fw_alloc_request out-of-bounds (EUVD-2025-32015 / Nessus ID 279908)
A vulnerability classified as critical was found in Linux Kernel up to 6.1.1. This impacts the function brcmf_fw_alloc_request of the file drivers/net/wireless/broadcom/brcm80211/brcmfmac/firmware.c. Such manipulation leads to out-of-bounds read.
This vulnerability is documented as CVE-2022-50551. The attack requires being on the local network. There is not any exploit available.
Upgrading the affected component is advised.
OSV
CVE-2022-50551: In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: Fix potential shift-out-of-bounds in brcmf_fw_alloc_request() This
osv·2025-10-07·CVSS 7.1
CVE-2022-50551 [HIGH] CVE-2022-50551: In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: Fix potential shift-out-of-bounds in brcmf_fw_alloc_request() This
In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: Fix potential shift-out-of-bounds in brcmf_fw_alloc_request() This patch fixes a shift-out-of-bounds in brcmfmac that occurs in BIT(chiprev) when a 'chiprev' provided by the device is too large. It should also not be equal to or greater than BITS_PER_TYPE(u32) as we do bitwise AND with a u32 variable and BIT(chiprev). The patch adds a check that makes the function return NULL if that is the case. Note that the NULL case is later handled by the bus-specific caller, brcmf_usb_probe_cb() or brcmf_usb_reset_resume(), for example. Found by a modified version of syzkaller. UBSAN: shift-out-of-bounds in drivers/net/wireless/broadcom/brcm80211/brcmfmac/firmware.c shift exponent 151055786 is too large for 64-bit typ
GHSA
GHSA-3cj2-mw4r-3p6w: In the Linux kernel, the following vulnerability has been resolved:
wifi: brcmfmac: Fix potential shift-out-of-bounds in brcmf_fw_alloc_request()
Th
ghsa_unreviewed·2025-10-07
CVE-2022-50551 [HIGH] CWE-125 GHSA-3cj2-mw4r-3p6w: In the Linux kernel, the following vulnerability has been resolved:
wifi: brcmfmac: Fix potential shift-out-of-bounds in brcmf_fw_alloc_request()
Th
In the Linux kernel, the following vulnerability has been resolved:
wifi: brcmfmac: Fix potential shift-out-of-bounds in brcmf_fw_alloc_request()
This patch fixes a shift-out-of-bounds in brcmfmac that occurs in
BIT(chiprev) when a 'chiprev' provided by the device is too large.
It should also not be equal to or greater than BITS_PER_TYPE(u32)
as we do bitwise AND with a u32 variable and BIT(chiprev). The patch
adds a check that makes the function return NULL if that is the case.
Note that the NULL case is later handled by the bus-specific caller,
brcmf_usb_probe_cb() or brcmf_usb_reset_resume(), for example.
Found by a modified version of syzkaller.
UBSAN: shift-out-of-bounds in drivers/net/wireless/broadcom/brcm80211/brcmfmac/firmware.c
shift exponent 151055786 is too large for 64-bit
Red Hat
kernel: wifi: brcmfmac: Fix potential shift-out-of-bounds in brcmf_fw_alloc_request()
vendor_redhat·2025-10-07·CVSS 7.1
CVE-2022-50551 [HIGH] CWE-682 kernel: wifi: brcmfmac: Fix potential shift-out-of-bounds in brcmf_fw_alloc_request()
kernel: wifi: brcmfmac: Fix potential shift-out-of-bounds in brcmf_fw_alloc_request()
In the Linux kernel, the following vulnerability has been resolved:
wifi: brcmfmac: Fix potential shift-out-of-bounds in brcmf_fw_alloc_request()
This patch fixes a shift-out-of-bounds in brcmfmac that occurs in
BIT(chiprev) when a 'chiprev' provided by the device is too large.
It should also not be equal to or greater than BITS_PER_TYPE(u32)
as we do bitwise AND with a u32 variable and BIT(chiprev). The patch
adds a check that makes the function return NULL if that is the case.
Note that the NULL case is later handled by the bus-specific caller,
brcmf_usb_probe_cb() or brcmf_usb_reset_resume(), for example.
Found by a modified version of syzkaller.
UBSAN: shift-out-of-bounds in drivers/net/wireless/broa
Debian
CVE-2022-50551: linux - In the Linux kernel, the following vulnerability has been resolved: wifi: brcmf...
vendor_debian·2022·CVSS 7.1
CVE-2022-50551 [HIGH] CVE-2022-50551: linux - In the Linux kernel, the following vulnerability has been resolved: wifi: brcmf...
In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: Fix potential shift-out-of-bounds in brcmf_fw_alloc_request() This patch fixes a shift-out-of-bounds in brcmfmac that occurs in BIT(chiprev) when a 'chiprev' provided by the device is too large. It should also not be equal to or greater than BITS_PER_TYPE(u32) as we do bitwise AND with a u32 variable and BIT(chiprev). The patch adds a check that makes the function return NULL if that is the case. Note that the NULL case is later handled by the bus-specific caller, brcmf_usb_probe_cb() or brcmf_usb_reset_resume(), for example. Found by a modified version of syzkaller. UBSAN: shift-out-of-bounds in drivers/net/wireless/broadcom/brcm80211/brcmfmac/firmware.c shift exponent 151055786 is too large for 64-bit typ
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/0b12d2aa264bac35bff9b5399bb162262b2b8949https://git.kernel.org/stable/c/1db036d13e10809943c2dce553e2fa7fc9c6cd80https://git.kernel.org/stable/c/4c8fc44c44b97854623c56363c359f711fc0b887https://git.kernel.org/stable/c/579c9b9838e8a73f6e93ddece07972c241514dcchttps://git.kernel.org/stable/c/5b06a8a25eba07628313aa3c5496522eff97be53https://git.kernel.org/stable/c/81d17f6f3331f03c8eafdacea68ab773426c1e3chttps://git.kernel.org/stable/c/87792567d9ed93fd336d2c3b8d7870f44e141e6dhttps://git.kernel.org/stable/c/9d2f70fa2c7cc6c73a420ff15682454782d3d6f6https://git.kernel.org/stable/c/bc45aa1911bf699b9905f12414e3c1879d6b784fhttps://git.kernel.org/stable/c/ffb589963df103caaf062081a32db0b9e1798660
2025-10-07
Published