CVE-2022-50358

medium

Description

In the Linux kernel, the following vulnerability has been resolved: brcmfmac: return error when getting invalid max_flowrings from dongle When firmware hit trap at initialization, host will read abnormal max_flowrings number from dongle, and it will cause kernel panic when doing iowrite to initialize dongle ring. To detect this error at early stage, we directly return error when getting invalid max_flowrings(>256).

References

https://git.kernel.org/stable/c/87f126b25fa8562196f0f4c0aa46a446026199bf

https://git.kernel.org/stable/c/3cc9299036bdb647408e11e41de3eb1ff6d428cd

https://git.kernel.org/stable/c/2e8bb402b060a6c22160de3d72cee057698177c8

https://git.kernel.org/stable/c/2aca4f3734bd717e04943ddf340d49ab62299a00

https://git.kernel.org/stable/c/200347eb3b2608cc8b54c13dd1d5e03809ba2eb2

https://git.kernel.org/stable/c/10c4b63d09a5b0ebf1b61af1dae7f25555cf58b6

Details

Source: Mitre, NVD

Published: 2025-09-17

Updated: 2025-09-18

Risk Information

CVSS v2

Base Score: 4.9

Vector: CVSS2#AV:L/AC:L/Au:N/C:N/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 5.5

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: Medium

EPSS

EPSS: 0.00024