PT-2025-8262 · Linux+5 · Linux Kernel+5

·

CVE-2022-49328

·

Publicado

2022-01-01

·

Atualizado

2026-08-23

CVSS v3.1

8.8

Alta

VetorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Nome do Software Vulnerável e Versões Afetadas Linux kernel (versões afetadas não especificadas)
Descrição Um problema de use-after-free existe no driver sem fio mt76. O problema ocorre na função mt76 txq schedule() ao acessar o ponteiro mtxq->wcid. Isso pode ser mitigado protegendo a variável mtxq->wcid com um rcu lock entre a função mt76 txq schedule() e as funções sta info alloc() e sta info free(). A exploração deste problema pode impactar potencialmente a confidencialidade, integridade e disponibilidade das informações protegidas.
Recomendações No momento, não há informações sobre uma versão mais recente que contenha uma correção para esta vulnerabilidade.

Exploit

DoS

Use After Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2025_16880
BDU:2025-10581
CESA-2023_2951
CVE-2022-49328
OESA-2025-1433
OESA-2025-1434
RHSA-2023:2458
RHSA-2023:2951
RHSA-2023_2458
RHSA-2023_2951
RHSA-2025:10179
RHSA-2025:10828
RHSA-2025:9493
RHSA-2025:9494
RHSA-2025:9498
SUSE-SU-2025:1027-1
SUSE-SU-2025:1176-1
SUSE-SU-2025:1183-1
SUSE-SU-2025:1241-1
SUSE-SU-2025_1027-1
SUSE-SU-2025_1241-1

Produtos afetados

Astra Linux
Centos
Debian
Linux Kernel
Red Hat
Suse