Home

Description

In the Linux kernel, the following vulnerability has been resolved: brcmfmac: return error when getting invalid max_flowrings from dongle When firmware hit trap at initialization, host will read abnormal max_flowrings number from dongle, and it will cause kernel panic when doing iowrite to initialize dongle ring. To detect this error at early stage, we directly return error when getting invalid max_flowrings(>256).

PUBLISHED Reserved 2025-09-17 | Published 2025-09-17 | Updated 2025-09-17 | Assigner Linux

Product status

Default status
unaffected

1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 (git) before 3cc9299036bdb647408e11e41de3eb1ff6d428cd
affected

1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 (git) before 2e8bb402b060a6c22160de3d72cee057698177c8
affected

1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 (git) before 10c4b63d09a5b0ebf1b61af1dae7f25555cf58b6
affected

1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 (git) before 87f126b25fa8562196f0f4c0aa46a446026199bf
affected

1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 (git) before 200347eb3b2608cc8b54c13dd1d5e03809ba2eb2
affected

1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 (git) before 2aca4f3734bd717e04943ddf340d49ab62299a00
affected

Default status
affected

5.4.229 (semver)
unaffected

5.10.163 (semver)
unaffected

5.15.86 (semver)
unaffected

6.0.16 (semver)
unaffected

6.1.2 (semver)
unaffected

6.2 (original_commit_for_fix)
unaffected

References

git.kernel.org/...c/3cc9299036bdb647408e11e41de3eb1ff6d428cd

git.kernel.org/...c/2e8bb402b060a6c22160de3d72cee057698177c8

git.kernel.org/...c/10c4b63d09a5b0ebf1b61af1dae7f25555cf58b6

git.kernel.org/...c/87f126b25fa8562196f0f4c0aa46a446026199bf

git.kernel.org/...c/200347eb3b2608cc8b54c13dd1d5e03809ba2eb2

git.kernel.org/...c/2aca4f3734bd717e04943ddf340d49ab62299a00

cve.org (CVE-2022-50358)

nvd.nist.gov (CVE-2022-50358)

Download JSON