CVE-2022-50852
published 2025-12-30CVE-2022-50852: In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7921: fix use after free in mt7921_acpi_read() Don't dereference "sar_root"…
PriorityP420medium5.1
EPSS
0.16%
5.8th percentile
In the Linux kernel, the following vulnerability has been resolved:
wifi: mt76: mt7921: fix use after free in mt7921_acpi_read()
Don't dereference "sar_root" after it has been freed.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.0.3-1 (bookworm) | linux 6.0.3-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= f965333e491e36adb0fa91e389fba8685b704fb6 < 3ed0b382cb36f6dac9f93b3a5533cfcd699409a5 | 3ed0b382cb36f6dac9f93b3a5533cfcd699409a5 |
| linux | linux | >= f965333e491e36adb0fa91e389fba8685b704fb6 < e7de4b4979bd8d313ec837931dde936653ca82ea | e7de4b4979bd8d313ec837931dde936653ca82ea |
| linux | linux_kernel | >= 0 < 6.0.3-1 | 6.0.3-1 |
| linux | linux_kernel | >= 0 < 6.0.3-1 | 6.0.3-1 |
| linux | linux_kernel | >= 0 < 6.0.3-1 | 6.0.3-1 |
| linux | linux_kernel | >= 6.0.0 < 6.0.3 | 6.0.3 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Linux Kernel up to 6.0.2 wifi mt7921_acpi_read use after free (WID-SEC-2025-2941)
vuldb·2026-04-26
CVE-2022-50852 [CRITICAL] Linux Kernel up to 6.0.2 wifi mt7921_acpi_read use after free (WID-SEC-2025-2941)
A vulnerability classified as critical has been found in Linux Kernel up to 6.0.2. This impacts the function mt7921_acpi_read of the component wifi. The manipulation leads to use after free.
This vulnerability is uniquely identified as CVE-2022-50852. The attack can only be initiated within the local network. No exploit exists.
It is recommended to upgrade the affected component.
GHSA
GHSA-78hp-5r4f-844r: In the Linux kernel, the following vulnerability has been resolved:
wifi: mt76: mt7921: fix use after free in mt7921_acpi_read()
Don't dereference "
ghsa_unreviewed·2025-12-30
CVE-2022-50852 GHSA-78hp-5r4f-844r: In the Linux kernel, the following vulnerability has been resolved:
wifi: mt76: mt7921: fix use after free in mt7921_acpi_read()
Don't dereference "
In the Linux kernel, the following vulnerability has been resolved:
wifi: mt76: mt7921: fix use after free in mt7921_acpi_read()
Don't dereference "sar_root" after it has been freed.
OSV
wifi: mt76: mt7921: fix use after free in mt7921_acpi_read()
osv·2025-12-30
CVE-2022-50852 wifi: mt76: mt7921: fix use after free in mt7921_acpi_read()
wifi: mt76: mt7921: fix use after free in mt7921_acpi_read()
In the Linux kernel, the following vulnerability has been resolved:
wifi: mt76: mt7921: fix use after free in mt7921_acpi_read()
Don't dereference "sar_root" after it has been freed.
OSV
CVE-2022-50852: In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7921: fix use after free in mt7921_acpi_read() Don't dereference "sa
osv·2025-12-30
CVE-2022-50852 CVE-2022-50852: In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7921: fix use after free in mt7921_acpi_read() Don't dereference "sa
In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7921: fix use after free in mt7921_acpi_read() Don't dereference "sar_root" after it has been freed.
Red Hat
kernel: wifi: mt76: mt7921: fix use after free in mt7921_acpi_read()
vendor_redhat·2025-12-30·CVSS 5.1
CVE-2022-50852 [MEDIUM] CWE-416 kernel: wifi: mt76: mt7921: fix use after free in mt7921_acpi_read()
kernel: wifi: mt76: mt7921: fix use after free in mt7921_acpi_read()
In the Linux kernel, the following vulnerability has been resolved:
wifi: mt76: mt7921: fix use after free in mt7921_acpi_read()
Don't dereference "sar_root" after it has been freed.
Statement: A use-after-free issue exists in mt7921_acpi_read() where sar_root->package.count was dereferenced after sar_root had already been freed. Triggering it typically requires privileged control over ACPI/firmware-provided data (or equivalent device/boot-time control), making real-world exploitation unlikely for unprivileged users. The most realistic outcome is driver misbehavior or a crash in debug/sanitized builds. The bug is a read-after-free that only affects a return value.
Package: kernel (Red Hat Enterprise Linux 10) - Not aff
Debian
CVE-2022-50852: linux - In the Linux kernel, the following vulnerability has been resolved: wifi: mt76:...
vendor_debian·2022
CVE-2022-50852 CVE-2022-50852: linux - In the Linux kernel, the following vulnerability has been resolved: wifi: mt76:...
In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7921: fix use after free in mt7921_acpi_read() Don't dereference "sar_root" after it has been freed.
Scope: local
bookworm: resolved (fixed in 6.0.3-1)
bullseye: resolved
forky: resolved (fixed in 6.0.3-1)
sid: resolved (fixed in 6.0.3-1)
trixie: resolved (fixed in 6.0.3-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2022-50852 kernel: wifi: mt76: mt7921: fix use after free in mt7921_acpi_read()
bugzilla·2025-12-30
CVE-2022-50852 [MEDIUM] CVE-2022-50852 kernel: wifi: mt76: mt7921: fix use after free in mt7921_acpi_read()
CVE-2022-50852 kernel: wifi: mt76: mt7921: fix use after free in mt7921_acpi_read()
In the Linux kernel, the following vulnerability has been resolved:
wifi: mt76: mt7921: fix use after free in mt7921_acpi_read()
Don't dereference "sar_root" after it has been freed.
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2025123045-CVE-2022-50852-978e@gregkh/T
Wiz
CVE-2022-50852 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
CVE-2022-50852 CVE-2022-50852 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2022-50852 :
Linux Kernel vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
wifi: mt76: mt7921: fix use after free in mt7921_acpi_read()
Don't dereference "sar_root" after it has been freed.
Source : NVD
Published December 30, 2025
CNA Score N/A
Affected Technologies
Linux Kernel
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 7.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
kernel-zfcpdump-devel-matched
kernel-zfcpdump-modules-core
Sources
NVD
Debian 12, 13, 14 Has Fix Added at: Dec 31, 2025
Echo Has Fix Added at: Dec 31, 2025
Red Hat 8, 9 Severity MEDIUM No Fix Added at: Dec 31,
2025-12-30
Published