Back

HIGH

kernel: use-after-free in ath9k_htc_probe_device() could cause an escalation of privileges

Published May 16, 2022

Description

A use-after-free flaw was found in the Linux kernel’s Atheros wireless adapter driver in the way a user forces the ath9k_htc_wait_for_target function to fail with some input messages. This flaw allows a local user to crash or potentially escalate their privileges on the system.

Affected products

Remediation

Red Hat statement

Keeping this issue Moderate, because the impact is limited: likely only possibility of memory leak and crash, but not privileges escalation and both kind of race condition that is hard to trigger.

Red Hat mitigation

To mitigate this issue, prevent the module ath9k from being loaded. Please see https://access.redhat.com/solutions/41278 for information on how to blacklist a kernel module to prevent it from loading automatically.

Weaknesses (1)

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published May 16, 2022
Updated Aug 3, 2024
Reserved May 12, 2022
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Feb 7, 2022
ENISA EUVD
Assigner redhat
Published May 16, 2022
Updated Aug 3, 2024
Exploited since n/a
EUVD-2022-24965