PT-2025-8218 · Linux+4 · Linux Kernel+4

Matthias Kretschmer

·

Published

2022-03-10

·

Updated

2025-09-29

·

CVE-2022-49290

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A potential double free issue in the Linux kernel's mac80211 module has been identified. This issue occurs when rejoining a mesh network, potentially causing memory corruption and kernel panics. The problem arises from the ieee80211 leave mesh() and ieee80211 join mesh() functions, where the ie data is freed twice. This can be reproduced using wpa supplicant with an encrypted mesh setup and calling specific iw commands to leave and rejoin the mesh. However, when using wpa supplicant, the issue is typically avoided due to a NETDEV DOWN/NETDEV UP cycle that resets the mesh.ie to NULL.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Double Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
BDU:2025-10247
CESA-2022_7683
CVE-2022-49290
OPENSUSE-SU-2025_1263-1
RHSA-2022:7683
RHSA-2022:8267
RHSA-2022_7683
RHSA-2022_8267
RHSA-2026:1442
RHSA-2026:1494
RHSA-2026:1495
RHSA-2026:1886
SUSE-SU-2025:01600-1
SUSE-SU-2025:1027-1
SUSE-SU-2025:1176-1
SUSE-SU-2025:1183-1
SUSE-SU-2025:1194-1
SUSE-SU-2025:1241-1
SUSE-SU-2025:1263-1
SUSE-SU-2025_01600-1
SUSE-SU-2025_1027-1
SUSE-SU-2025_1241-1
SUSE-SU-2025_1263-1

Affected Products

Astra Linux
Centos
Linux Kernel
Red Hat
Suse