PT-2025-8262 · Linux+5 · Linux Kernel+5

·

CVE-2022-49328

·

Published

2022-01-01

·

Updated

2026-08-23

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A use-after-free issue exists in the mt76 wireless driver. The problem occurs in the mt76 txq schedule() function when accessing the mtxq->wcid pointer. This can be mitigated by protecting the mtxq->wcid variable with an RCU lock between the mt76 txq schedule() function and the sta info alloc() and sta info free() functions. Exploitation of this issue could potentially impact the confidentiality, integrity, and availability of protected information.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
BDU:2025-10581
CESA-2023_2951
CVE-2022-49328
OESA-2025-1433
OESA-2025-1434
RHSA-2023:2458
RHSA-2023:2951
RHSA-2023_2458
RHSA-2023_2951
RHSA-2025:10179
RHSA-2025:10828
RHSA-2025:9493
RHSA-2025:9494
RHSA-2025:9498
SUSE-SU-2025:1027-1
SUSE-SU-2025:1176-1
SUSE-SU-2025:1183-1
SUSE-SU-2025:1241-1
SUSE-SU-2025_1027-1
SUSE-SU-2025_1241-1

Affected Products

Astra Linux
Centos
Debian
Linux Kernel
Red Hat
Suse