cbcvebase.
CVE-2022-50678
published 2025-12-09

CVE-2022-50678: In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: fix invalid address access when enabling SCAN log level The variable i is…

PriorityP424medium5.5
EPSS
0.23%
13.9th percentile
In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: fix invalid address access when enabling SCAN log level The variable i is changed when setting random MAC address and causes invalid address access when printing the value of pi->reqs[i]->reqid. We replace reqs index with ri to fix the issue. [ 136.726473] Unable to handle kernel access to user memory outside uaccess routines at virtual address 0000000000000000 [ 136.737365] Mem abort info: [ 136.740172] ESR = 0x96000004 [ 136.743359] Exception class = DABT (current EL), IL = 32 bits [ 136.749294] SET = 0, FnV = 0 [ 136.752481] EA = 0, S1PTW = 0 [ 136.755635] Data abort info: [ 136.758514] ISV = 0, ISS = 0x00000004 [ 136.762487] CM = 0, WnR = 0 [ 136.765522] user pgtable: 4k pages, 48-bit VAs, pgdp = 000000005c4e2577 [ 136.772265] [0000000000000000] pgd=0000000000000000 [ 136.777160] Internal error: Oops: 96000004 [#1] PREEMPT SMP [ 136.782732] Modules linked in: brcmfmac(O) brcmutil(O) cfg80211(O) compat(O) [ 136.789788] Process wificond (pid: 3175, stack limit = 0x00000000053048fb) [ 136.796664] CPU: 3 PID: 3175 Comm: wificond Tainted: G O 4.19.42-00001-g531a5f5 #1 [ 136.805532] Hardware name: Freescale i.MX8MQ EVK (DT) [ 136.810584] pstate: 60400005 (nZCv daif +PAN -UAO) [ 136.815429] pc : brcmf_pno_config_sched_scans+0x6cc/0xa80 [brcmfmac] [ 136.821811] lr : brcmf_pno_config_sched_scans+0x67c/0xa80 [brcmfmac] [ 136.828162] sp : ffff00000e9a3880 [ 136.831475] x29: ffff00000e9a3890 x28: ffff800020543400 [ 136.836786] x27: ffff8000b1008880 x26: ffff0000012bf6a0 [ 136.842098] x25: ffff80002054345c x24: ffff800088d22400 [ 136.847409] x23: ffff0000012bf638 x22: ffff0000012bf6d8 [ 136.852721] x21: ffff8000aced8fc0 x20: ffff8000ac164400 [ 136.858032] x19: ffff00000e9a3946 x18: 0000000000000000 [ 136.863343] x17: 0000000000000000 x16: 0000000000000000 [ 136.868655] x15: ffff0000093f3b37 x14: 0000000000000050 [ 136.873966] x13: 0000000000003135 x12: 0000000000000000 [ 136.879277] x11:

Affected

21 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.0.3-1 (bookworm)linux 6.0.3-1 (bookworm)
linuxlinux
linuxlinux>= efc2c1fa8e145b60a7805fa9b6c92ac0746fccc3 < 7ccb0529446ae68a8581916bfc95c353306d76ba7ccb0529446ae68a8581916bfc95c353306d76ba
linuxlinux>= efc2c1fa8e145b60a7805fa9b6c92ac0746fccc3 < 1c12d47a9017a7745585b57b9b0fdc0d8c50978e1c12d47a9017a7745585b57b9b0fdc0d8c50978e
linuxlinux>= efc2c1fa8e145b60a7805fa9b6c92ac0746fccc3 < 56a0ac48634155d2b866b99fba7e1dd8df4e280456a0ac48634155d2b866b99fba7e1dd8df4e2804
linuxlinux>= efc2c1fa8e145b60a7805fa9b6c92ac0746fccc3 < 50e45034c5802cedbf5b707364ea76ace29ad98450e45034c5802cedbf5b707364ea76ace29ad984
linuxlinux>= efc2c1fa8e145b60a7805fa9b6c92ac0746fccc3 < 75995ce1c926ee87bf93d58977c766b4e774471575995ce1c926ee87bf93d58977c766b4e7744715
linuxlinux>= efc2c1fa8e145b60a7805fa9b6c92ac0746fccc3 < 4d4dcfa6b4e85a878401f4fbae4cafc88cdcceb44d4dcfa6b4e85a878401f4fbae4cafc88cdcceb4
linuxlinux>= efc2c1fa8e145b60a7805fa9b6c92ac0746fccc3 < 826405a911473b6ee8bd2aa891cb2f03a13efa17826405a911473b6ee8bd2aa891cb2f03a13efa17
linuxlinux>= efc2c1fa8e145b60a7805fa9b6c92ac0746fccc3 < aa666b68e73fc06d83c070d96180b9010cf5a960aa666b68e73fc06d83c070d96180b9010cf5a960
linuxlinux_kernel>= 0 < 5.10.158-15.10.158-1
linuxlinux_kernel>= 0 < 6.0.3-16.0.3-1
linuxlinux_kernel>= 0 < 6.0.3-16.0.3-1
linuxlinux_kernel>= 0 < 6.0.3-16.0.3-1
linuxlinux_kernel>= 4.13.0 < 4.14.2964.14.296
linuxlinux_kernel>= 4.15.0 < 4.19.2624.19.262
linuxlinux_kernel>= 4.20.0 < 5.4.2205.4.220
linuxlinux_kernel>= 5.11.0 < 5.15.755.15.75
linuxlinux_kernel>= 5.16.0 < 5.19.175.19.17
linuxlinux_kernel>= 5.20.0 < 6.0.36.0.3
linuxlinux_kernel>= 5.5.0 < 5.10.1505.10.150
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.