PT-2025-37581 · Linux+5 · Linux Kernel+5
CVE-2022-50279
·
Published
2022-12-14
·
Updated
2025-10-23
CVSS v3.1
7.8
High
| Vector | AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions 6.1.0-rc8+ through 6.1.0-rc8+ #144
Description
This issue involves a global out-of-bounds bug in the
rtl8812ae phy set txpower limit() function within the rtlwifi module. The root cause is an incorrect comparison order of "prate section" leading to out-of-bounds access in the rtl8812ae eq n byte() function. The rtl8812ae eq n byte() function is similar to strcmp(), and the issue can be resolved by using strcmp() directly.Recommendations
Linux kernel versions prior to 6.1.0-rc8+ #144: Remove the
rtl8812ae eq n byte() function and use strcmp() instead.Exploit
Fix
DoS
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Centos
Linux Kernel
Red Hat
Suse
Rtlwifi