cbcvebase.
CVE-2022-50881
published 2025-12-30

CVE-2022-50881: In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k: Fix use-after-free in ath9k_hif_usb_disconnect() This patch fixes a…

PriorityP422high7
EPSS
0.18%
7.2th percentile
In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k: Fix use-after-free in ath9k_hif_usb_disconnect() This patch fixes a use-after-free in ath9k that occurs in ath9k_hif_usb_disconnect() when ath9k_destroy_wmi() is trying to access 'drv_priv' that has already been freed by ieee80211_free_hw(), called by ath9k_htc_hw_deinit(). The patch moves ath9k_destroy_wmi() before ieee80211_free_hw(). Note that urbs from the driver should be killed before freeing 'wmi' with ath9k_destroy_wmi() as their callbacks will access 'wmi'. Found by a modified version of syzkaller. BUG: KASAN: use-after-free in ath9k_destroy_wmi+0x38/0x40 Read of size 8 at addr ffff8881069132a0 by task kworker/0:1/7 CPU: 0 PID: 7 Comm: kworker/0:1 Tainted: G O 5.14.0+ #131 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.12.1-0-ga5cab58e9a3f-prebuilt.qemu.org 04/01/2014 Workqueue: usb_hub_wq hub_event Call Trace: dump_stack_lvl+0x8e/0xd1 print_address_description.constprop.0.cold+0x93/0x334 ? ath9k_destroy_wmi+0x38/0x40 ? ath9k_destroy_wmi+0x38/0x40 kasan_report.cold+0x83/0xdf ? ath9k_destroy_wmi+0x38/0x40 ath9k_destroy_wmi+0x38/0x40 ath9k_hif_usb_disconnect+0x329/0x3f0 ? ath9k_hif_usb_suspend+0x120/0x120 ? usb_disable_interface+0xfc/0x180 usb_unbind_interface+0x19b/0x7e0 ? usb_autoresume_device+0x50/0x50 device_release_driver_internal+0x44d/0x520 bus_remove_device+0x2e5/0x5a0 device_del+0x5b2/0xe30 ? __device_link_del+0x370/0x370 ? usb_remove_ep_devs+0x43/0x80 ? remove_intf_ep_devs+0x112/0x1a0 usb_disable_device+0x1e3/0x5a0 usb_disconnect+0x267/0x870 hub_event+0x168d/0x3950 ? rcu_read_lock_sched_held+0xa1/0xd0 ? hub_port_debounce+0x2e0/0x2e0 ? check_irq_usage+0x860/0xf20 ? drain_workqueue+0x281/0x360 ? lock_release+0x640/0x640 ? rcu_read_lock_sched_held+0xa1/0xd0 ? rcu_read_lock_bh_held+0xb0/0xb0 ? lockdep_hardirqs_on_prepare+0x273/0x3e0 process_one_work+0x92b/0x1460 ? pwq_dec_nr_in_flight+0x330/0x330 ? rwlock_bug.part.0+0x90/0x90 worker_thread+0x95/0xe00

Affected

29 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.20-1 (bookworm)linux 6.1.20-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 4.14.185 < 4.154.15
linuxlinux>= 4.19.129 < 4.204.20
linuxlinux>= 4.4.228 < 4.54.5
linuxlinux>= 4.9.228 < 4.104.10
linuxlinux>= 5.4.47 < 5.55.5
linuxlinux>= 5.6.19 < 5.75.7
linuxlinux>= 5.7.3 < 5.85.8
linuxlinux>= abeaa85054ff8cfe8b99aafc5c70ea067e5d0908 < 99ff971b62e5bd5dee65bbe9777375206f5db79199ff971b62e5bd5dee65bbe9777375206f5db791
linuxlinux>= abeaa85054ff8cfe8b99aafc5c70ea067e5d0908 < 634a5471a6bd774c0d0fa448dfa6ec593e899ec9634a5471a6bd774c0d0fa448dfa6ec593e899ec9
linuxlinux>= abeaa85054ff8cfe8b99aafc5c70ea067e5d0908 < 1f137c634a8c8faba648574f687805641e62f92e1f137c634a8c8faba648574f687805641e62f92e
linuxlinux>= abeaa85054ff8cfe8b99aafc5c70ea067e5d0908 < de15e8bbd9eb26fe94a06d0ec7be82dc490eb729de15e8bbd9eb26fe94a06d0ec7be82dc490eb729
linuxlinux>= abeaa85054ff8cfe8b99aafc5c70ea067e5d0908 < f099c5c9e2ba08a379bd354a82e05ef839ae29acf099c5c9e2ba08a379bd354a82e05ef839ae29ac
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.20-16.1.20-1
linuxlinux_kernel>= 0 < 6.1.20-16.1.20-1
linuxlinux_kernel>= 0 < 6.1.20-16.1.20-1
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.