mt76: fix monitor mode crash with sdio driver
Published Feb 26, 2025
5.5
MEDIUMCVSS 3.1
EPSS 0.25%
Description
mt7921s driver may receive frames with fragment buffers. If there is a CTS packet received in monitor mode, the payload is 10 bytes only and need 6 bytes header padding after RXD buffer. However, only RXD in the first linear buffer, if we pull buffer size RXD-size+6 bytes with skb_pull(), that would trigger "BUG_ON(skb->len < skb->data_len)" in __skb_pull().
To avoid the nonlinear buffer issue, enlarge the RXD size from 128 to 256 to make sure all MCU operation in linear buffer.
[ 52.007562] kernel BUG at include/linux/skbuff.h:2313! [ 52.007578] Internal error: Oops - BUG: 0 [#1] PREEMPT SMP [ 52.007987] pc : skb_pull+0x48/0x4c [ 52.008015] lr : mt7921_queue_rx_skb+0x494/0x890 [mt7921_common] [ 52.008361] Call trace: [ 52.008377] skb_pull+0x48/0x4c [ 52.008400] mt76s_net_worker+0x134/0x1b0 [mt76_sdio 35339a92c6eb7d4bbcc806a1d22f56365565135c] [ 52.008431] __mt76_worker_fn+0xe8/0x170 [mt76 ef716597d11a77150bc07e3fdd68eeb0f9b56917] [ 52.008449] kthread+0x148/0x3ac [ 52.008466] ret_from_fork+0x10/0x30
Affected products
-
Affected
- ≥ , <
- ≥ , <
- ≥ , <
-
Affected
- 5.16
Unaffected
- ≥ 0, < 5.16
- ≥ 5.16.20, ≤ 5.16.*
- ≥ 5.17.3, ≤ 5.17.*
- 5.18
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
- ≥ 4.16 · < 5.15.34
- ≥ 5.16 · < 5.16.20
- ≥ 5.17 · < 5.17.3
No data.
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
No CWE recorded.
References (9)
- https://access.redhat.com/security/cve/CVE-2022-49112 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2347778 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-54490 Advisory
- https://git.kernel.org/stable/c/123bc712b1de0805f9d683687e17b1ec2aba0b68 Patch
- https://git.kernel.org/stable/c/95e2af01669c7a3cb7a933cefa06361f9db15059 Patch
- https://git.kernel.org/stable/c/c37b4cab3d97ef64b206fca4d9daabd9aff7356e Patch
- https://lore.kernel.org/linux-cve-announce/2025022602-CVE-2022-49112-3f57@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2022-49112
- https://www.cve.org/CVERecord?id=CVE-2022-49112
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data