CVE-2022-49129

In the Linux kernel, the following vulnerability has been resolved: mt76: mt7921: fix crash when startup fails. If the nic fails to start, it is possible that the reset_work has already been scheduled. Ensure the work item is canceled so we do not have use-after-free crash in case cleanup is called before the work item is executed. This fixes crash on my x86_64 apu2 when mt7921k radio fails to work. Radio still fails, but OS does not crash.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

25 Mar 2025, 16:18

Type Values Removed Values Added
References () https://git.kernel.org/stable/c/38fbe806645090c07aa97171f20fc62c3d7d3a98 - () https://git.kernel.org/stable/c/38fbe806645090c07aa97171f20fc62c3d7d3a98 - Patch
References () https://git.kernel.org/stable/c/827e7799c61b978fbc2cc9dac66cb62401b2b3f0 - () https://git.kernel.org/stable/c/827e7799c61b978fbc2cc9dac66cb62401b2b3f0 - Patch
References () https://git.kernel.org/stable/c/ac1260b661c2ef0d0a56680cdb5672b931b7be8f - () https://git.kernel.org/stable/c/ac1260b661c2ef0d0a56680cdb5672b931b7be8f - Patch
References () https://git.kernel.org/stable/c/c1a5e6002ec441a3b9fb4d048b4b49ae93409a46 - () https://git.kernel.org/stable/c/c1a5e6002ec441a3b9fb4d048b4b49ae93409a46 - Patch
Summary
  • (es) En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: mt76: mt7921: se corrige el bloqueo cuando falla el inicio. Si la NIC no se inicia, es posible que ya se haya programado el reset_work. Asegúrese de que el elemento de trabajo se cancele para que no tengamos un bloqueo de use-after-free en caso de que se llame a la limpieza antes de que se ejecute el elemento de trabajo. Esto corrige el bloqueo en mi apu2 x86_64 cuando la radio mt7921k no funciona. La radio sigue fallando, pero el SO no se bloquea.
First Time Linux
Linux linux Kernel
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

27 Feb 2025, 19:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
CWE CWE-416

26 Feb 2025, 07:00

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-26 07:00

Updated : 2025-03-25 16:18


NVD link : CVE-2022-49129

Mitre link : CVE-2022-49129

CVE.ORG link : CVE-2022-49129


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-416

Use After Free