PT-2025-26090 · Linux+3 · Linux Kernel+3

Published

2023-05-09

·

Updated

2025-07-28

·

CVE-2022-50164

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.19.0-rc3+
Description A vulnerability in the Linux kernel has been resolved, related to the wifi component, specifically in the iwlwifi mvm module. The issue occurs when station queues are disabled, and the related lists are not emptied, potentially causing a list add corruption bug. This can happen when a new element is added to the list in iwl mvm mac wake tx queue, matching with an old one and producing a kernel bug. The vulnerability is related to the function iwl mvm mac wake tx queue and the module iwlmvm.
Recommendations To resolve the issue, update to a version of the Linux kernel that includes the fix for the vulnerability, which is version 5.19.0-rc3 or later. As a temporary workaround, consider disabling the iwl mvm mac wake tx queue function until a patch is available. Restrict access to the vulnerable module iwlmvm to minimize the risk of exploitation.

Exploit

Fix

Double Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-50164
RHSA-2022:8809
RHSA-2023:2458
RHSA-2023:2951
RHSA-2023_2458
SUSE-SU-2025:02264-1
SUSE-SU-2025:02308-1
SUSE-SU-2025:02320-1
SUSE-SU-2025:02321-1
SUSE-SU-2025:02322-1
SUSE-SU-2025:02537-1
SUSE-SU-2025:2264-1
SUSE-SU-2025_02264-1
SUSE-SU-2025_02308-1
SUSE-SU-2025_02537-1

Affected Products

Astra Linux
Linux Kernel
Red Hat
Suse