PT-2025-8163 · Linux+4 · Linux Kernel+4

Syzbot

·

Published

2022-11-08

·

Updated

2025-09-29

·

CVE-2022-49235

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A vulnerability in the Linux kernel has been identified, specifically in the ath9k htc module. The issue is caused by missing field initialization in the htc connect service() and htc issue send() functions. This results in uninitialized values being used, leading to potential information leaks. The vulnerability was reported by Syzbot, which identified two KMSAN bugs in the ath9k module. The bugs are caused by the lack of initialization of the svc meta len and pad variables in htc connect service() and the htc frame hdr::control array in htc issue send(). To fix the issue, the svc meta len variable is initialized to 0, and the htc frame hdr::control array is zeroed out.
Recommendations As a temporary workaround, consider disabling the htc connect service() function until a patch is available. Restrict access to the vulnerable ath9k htc module to minimize the risk of exploitation. Avoid using the htc issue send() function in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use of Uninitialized Resource

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
CESA-2022_7683
CVE-2022-49235
OESA-2025-1370
OPENSUSE-SU-2025_1263-1
RHSA-2022:7683
RHSA-2022:8267
RHSA-2022_7683
RHSA-2022_8267
SUSE-SU-2025:01983-1
SUSE-SU-2025:1027-1
SUSE-SU-2025:1176-1
SUSE-SU-2025:1183-1
SUSE-SU-2025:1194-1
SUSE-SU-2025:1241-1
SUSE-SU-2025:1263-1
SUSE-SU-2025_01983-1
SUSE-SU-2025_1027-1
SUSE-SU-2025_1241-1
SUSE-SU-2025_1263-1

Affected Products

Astra Linux
Centos
Linux Kernel
Red Hat
Suse