PT-2025-37599 · Linux+5 · Linux Kernel+5

Published

2022-10-11

·

Updated

2025-10-23

·

CVE-2022-50297

CVSS v2.0

6.0

Medium

VectorAV:L/AC:H/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel contains a flaw within the ath9k module related to USB endpoint handling. The issue occurs when a USB device identifies as an ATH9K but lacks the expected endpoints, specifically when an interrupt endpoint is present where a bulk endpoint is expected. This can lead to kernel errors when handling such devices. The vulnerability was found by Linux Verification Center (linuxtesting.org) using Syzkaller.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Access Control

Information Disclosure

Incorrect Privilege Assignment

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
BDU:2026-06078
CESA-2023_7077
CVE-2022-50297
OESA-2025-2406
RHSA-2023:6583
RHSA-2023:7077
RHSA-2023_6583
RHSA-2023_7077
SUSE-SU-2025:03614-1
SUSE-SU-2025:03615-1
SUSE-SU-2025:03628-1
SUSE-SU-2025:3716-1
SUSE-SU-2025:3761-1

Affected Products

Astra Linux
Centos
Linux Kernel
Red Hat
Suse
Ath9K