CVE-2022-50358

MEDIUM

Linux Kernel - Denial of Service via Invalid max_flowrings Value

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: brcmfmac: return error when getting invalid max_flowrings from dongle When firmware hit trap at initialization, host will read abnormal max_flowrings number from dongle, and it will cause kernel panic when doing iowrite to initialize dongle ring. To detect this error at early stage, we directly return error when getting invalid max_flowrings(>256).

Scores

CVSS v3 4.2
EPSS 0.0027
EPSS Percentile 19.8%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (20)
linux/Kernel 3.17.0 - 5.4.229linux
linux/Kernel 5.11.0 - 5.15.86linux
linux/Kernel 5.16.0 - 6.0.16linux
linux/Kernel 5.5.0 - 5.10.163linux
linux/Kernel 6.1.0 - 6.1.2linux
Linux/Linux < 3.17
Linux/Linux 3.17
Linux/Linux 5.10.163 - 5.10.*
Linux/Linux 5.15.86 - 5.15.*
Linux/Linux 5.4.229 - 5.4.*
... and 10 more
Published Sep 17, 2025
Tracked Since Feb 18, 2026