CVE-2022-50740
In the Linux kernel, the following vulnerability has been resolved:
wifi: ath9k: hif_usb: fix memory leak of urbs in ath9k_hif_usb_dealloc_tx_urbs()
Syzkaller reports a long-known leak of urbs in ath9k_hif_usb_dealloc_tx_urbs().
The cause of the leak is that usb_get_urb() is called but usb_free_urb() (or usb_put_urb()) is not called inside usb_kill_urb() as urb->dev or urb->ep fields have not been initialized and usb_kill_urb() returns immediately.
The patch removes trying to kill urbs located in hif_dev->tx.tx_buf because hif_dev->tx.tx_buf is not supposed to contain urbs which are in pending state (the pending urbs are stored in hif_dev->tx.tx_pending). The tx.tx_lock is acquired so there should not be any changes in the list.
Leer descripción completaMostrar menos
Found by Linux Verification Center (linuxtesting.org) with Syzkaller.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.28%
- Percentil entre todas las CVEs puntuadas: 19
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/08aa0537ec8cf29ceccae98acc1a534fc12598c1
- https://git.kernel.org/stable/c/134ae5eba41294eff76e4be20d6001b8f0192207
- https://git.kernel.org/stable/c/472312fef2b9eccaa03bd59e0ab2527da945e736
- https://git.kernel.org/stable/c/9850791d389b342ae6e573fe8198db0b4d338352
- https://git.kernel.org/stable/c/c05189a429fdb371dd455c3c466d67ac2ebff152
- https://git.kernel.org/stable/c/c2a94de38c74e86f49124ac14f093d6a5c377a90
- https://git.kernel.org/stable/c/c3fb3e9a2c0c1a0fa492d90eb19bcfa92a5f884d
- https://git.kernel.org/stable/c/d856f7574bcc1d81de565a857caf32f122cd7ce0
- https://git.kernel.org/stable/c/eddbb8f7620f9f8008b090a6e10c460074ca575a
JSON original (NVD)
Mostrar
{
"id": "CVE-2022-50740",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6f0706ef39fecc6bf56d67728fe0c94e26b43e9d",
"lessThan": "134ae5eba41294eff76e4be20d6001b8f0192207",
"versionType": "git"
},
{
"status": "affected",
"version": "795d57a558d106b8a5bc2bd7aeaf707d9a099244",
"lessThan": "472312fef2b9eccaa03bd59e0ab2527da945e736",
"versionType": "git"
},
{
"status": "affected",
"version": "df4318440c1568b7dedc5f7d4e617d0e297a1313",
"lessThan": "eddbb8f7620f9f8008b090a6e10c460074ca575a",
"versionType": "git"
},
{
"status": "affected",
"version": "a9990ed2d7ca9339d37c7f67d6f5cb298c3f1b34",
"lessThan": "9850791d389b342ae6e573fe8198db0b4d338352",
"versionType": "git"
},
{
"status": "affected",
"version": "03fb92a432ea5abe5909bca1455b7e44a9380480",
"lessThan": "c3fb3e9a2c0c1a0fa492d90eb19bcfa92a5f884d",
"versionType": "git"
},
{
"status": "affected",
"version": "03fb92a432ea5abe5909bca1455b7e44a9380480",
"lessThan": "d856f7574bcc1d81de565a857caf32f122cd7ce0",
"versionType": "git"
},
{
"status": "affected",
"version": "03fb92a432ea5abe5909bca1455b7e44a9380480",
"lessThan": "c05189a429fdb371dd455c3c466d67ac2ebff152",
"versionType": "git"
},
{
"status": "affected",
"version": "03fb92a432ea5abe5909bca1455b7e44a9380480",
"lessThan": "08aa0537ec8cf29ceccae98acc1a534fc12598c1",
"versionType": "git"
},
{
"status": "affected",
"version": "03fb92a432ea5abe5909bca1455b7e44a9380480",
"lessThan": "c2a94de38c74e86f49124ac14f093d6a5c377a90",
"versionType": "git"
},
{
"status": "affected",
"version": "b92e116ae36f498858dbb18e29a066c3f5348965",
"versionType": "git"
},
{
"status": "affected",
"version": "7f5972267295fe49f8da8eb42bc2eb3d140860c0",
"versionType": "git"
},
{
"status": "affected",
"version": "2d72d5ce63c92f56b9f978e8befb5838144176b9",
"versionType": "git"
},
{
"status": "affected",
"version": "4.9.241",
"lessThan": "4.9.337",
"versionType": "semver"
},
{
"status": "affected",
"version": "4.14.203",
"lessThan": "4.14.303",
"versionType": "semver"
},
{
"status": "affected",
"version": "4.19.154",
"lessThan": "4.19.270",
"versionType": "semver"
},
{
"status": "affected",
"version": "5.4.73",
"lessThan": "5.4.229",
"versionType": "semver"
},
{
"status": "affected",
"version": "4.4.241",
"lessThan": "4.5",
"versionType": "semver"
},
{
"status": "affected",
"version": "5.8.17",
"lessThan": "5.9",
"versionType": "semver"
},
{
"status": "affected",
"version": "5.9.2",
"lessThan": "5.10",
"versionType": "semver"
}
],
"programFiles": [
"drivers/net/wireless/ath/ath9k/hif_usb.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5.10"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "5.10",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "4.9.337",
"versionType": "semver",
"lessThanOrEqual": "4.9.*"
},
{
"status": "unaffected",
"version": "4.14.303",
"versionType": "semver",
"lessThanOrEqual": "4.14.*"
},
{
"status": "unaffected",
"version": "4.19.270",
"versionType": "semver",
"lessThanOrEqual": "4.19.*"
},
{
"status": "unaffected",
"version": "5.4.229",
"versionType": "semver",
"lessThanOrEqual": "5.4.*"
},
{
"status": "unaffected",
"version": "5.10.163",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.86",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.0.16",
"versionType": "semver",
"lessThanOrEqual": "6.0.*"
},
{
"status": "unaffected",
"version": "6.1.2",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/net/wireless/ath/ath9k/hif_usb.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2025-12-24T13:16:00.703",
"references": [
{
"url": "https://git.kernel.org/stable/c/08aa0537ec8cf29ceccae98acc1a534fc12598c1",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/134ae5eba41294eff76e4be20d6001b8f0192207",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/472312fef2b9eccaa03bd59e0ab2527da945e736",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/9850791d389b342ae6e573fe8198db0b4d338352",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/c05189a429fdb371dd455c3c466d67ac2ebff152",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/c2a94de38c74e86f49124ac14f093d6a5c377a90",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/c3fb3e9a2c0c1a0fa492d90eb19bcfa92a5f884d",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/d856f7574bcc1d81de565a857caf32f122cd7ce0",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/eddbb8f7620f9f8008b090a6e10c460074ca575a",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Deferred",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath9k: hif_usb: fix memory leak of urbs in ath9k_hif_usb_dealloc_tx_urbs()\n\nSyzkaller reports a long-known leak of urbs in\nath9k_hif_usb_dealloc_tx_urbs().\n\nThe cause of the leak is that usb_get_urb() is called but usb_free_urb()\n(or usb_put_urb()) is not called inside usb_kill_urb() as urb->dev or\nurb->ep fields have not been initialized and usb_kill_urb() returns\nimmediately.\n\nThe patch removes trying to kill urbs located in hif_dev->tx.tx_buf\nbecause hif_dev->tx.tx_buf is not supposed to contain urbs which are in\npending state (the pending urbs are stored in hif_dev->tx.tx_pending).\nThe tx.tx_lock is acquired so there should not be any changes in the list.\n\nFound by Linux Verification Center (linuxtesting.org) with Syzkaller."
}
],
"lastModified": "2026-06-17T05:24:05.880",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}