PT-2025-8436 · Linux+2 · Linux Kernel+2

Dan Carpenter

·

Published

2022-04-23

·

Updated

2025-06-17

·

CVE-2022-49503

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A potential out of bounds access issue has been identified in the Linux kernel, specifically in the ath9k htc driver. The issue arises when the rxstatus->rs keyix value is passed to the test bit() function without proper validation, potentially leading to unauthorized access. The vulnerable code is located in the ath9k cmn rx accept() function in the drivers/net/wireless/ath/ath9k/common.c file. The rx stats->rs keyix variable is considered untrusted data.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-03678
CVE-2022-49503
OESA-2025-1370
OPENSUSE-SU-2025_1263-1
RHSA-2026:2573
RHSA-2026:2577
SUSE-SU-2025:01983-1
SUSE-SU-2025:1027-1
SUSE-SU-2025:1176-1
SUSE-SU-2025:1183-1
SUSE-SU-2025:1194-1
SUSE-SU-2025:1241-1
SUSE-SU-2025:1263-1
SUSE-SU-2025_01983-1
SUSE-SU-2025_1027-1
SUSE-SU-2025_1241-1
SUSE-SU-2025_1263-1

Affected Products

Astra Linux
Linux Kernel
Suse