wifi: ath9k: hif_usb: Fix use-after-free in ath9k_hif_usb_reg_in_cb()
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k: hif_usb: Fix use-after-free in ath9k_hif_usb_reg_in_cb() It is possible that skb is freed in ath9k_htc_rx_msg(), then usb_submit_urb() fails and we try to free skb again. It causes use-after-free bug. Moreover, if alloc_skb() fails, urb->context becomes NULL but rx_buf is not freed and there can be a memory leak. The patch removes unnecessary nskb and makes skb processing more clear: it is supposed that ath9k_htc_rx_msg() either frees old skb or passes its managing to another callback function. Found by Linux Verification Center (linuxtesting.org) with Syzkaller.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-50829
Credits & Attribution
No credits recorded in the NVD database.
References
- https://git.kernel.org/stable/c/5e8751a977a49a6e00cce1a8da5ca16da83f9c8c
- https://git.kernel.org/stable/c/f127c2b4c967025e5c3a4ce7e13b79135d46a33d
- https://git.kernel.org/stable/c/0c8dd2ea4b419da96ab4953e4967e9363e2f8a4f
- https://git.kernel.org/stable/c/988bd27de2484faf17afe0408db2e3d9e5ac61fc
- https://git.kernel.org/stable/c/98d9172822dc6f38138333941984bd759a89d419
- https://git.kernel.org/stable/c/355f16f756aad0c95cdaa0c14a34ab4137d32815
- https://git.kernel.org/stable/c/53b9bb1a00c4285ee7f58a11129dbea015db61bc
- https://git.kernel.org/stable/c/71fc0ad671a62c494d2aec731baeabd3bfe6c95d
- https://git.kernel.org/stable/c/dd95f2239fc846795fc926787c3ae0ca701c9840
More from Linux
View All →Affected Vendor
Linux
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.