SB20251226288 - Use of uninitialized resource in Linux kernel ath ath9k driver
Published: December 26, 2025 Updated: December 31, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Use of uninitialized resource (CVE-ID: CVE-2022-50709)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to use of uninitialized resource within the ath9k_htc_txcompletion_cb() and ath9k_htc_rx_msg() functions in drivers/net/wireless/ath/ath9k/htc_hst.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0d2649b288b7b9484e3d4380c0d6c4720a17e473
- https://git.kernel.org/stable/c/2c485f4f2a64258acc5228e78ffb828c68d9e770
- https://git.kernel.org/stable/c/4891a50f5ed8bfcb8f2a4b816b0676f398687783
- https://git.kernel.org/stable/c/84242f15f911f34aec9b22f99d1e9bff19723dbe
- https://git.kernel.org/stable/c/9661724f6206bd606ecf13acada676a9975d230b
- https://git.kernel.org/stable/c/b1b4144508adfc585e43856b31baaf9008a3beb4
- https://git.kernel.org/stable/c/b383e8abed41cc6ff1a3b34de75df9397fa4878c
- https://git.kernel.org/stable/c/f3d2a3b7e290d0bdbddfcee5a6c3d922e2b7e02a
- https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.296