CVE-2022-50740: Linux
EPSS: 0.3% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k: hif_usb: fix memory leak of urbs in ath9k_hif_usb_dealloc_tx_urbs() Syzkaller reports a long-known leak of urbs in ath9k_hif_usb_dealloc_tx_urbs(). The cause of the leak is that usb_get_urb() is called but usb_free_urb() (or usb_put_urb()) is not called inside usb_kill_urb() as urb->dev or urb->ep fields have not been initialized and usb_kill_urb() returns immediately. The patch removes trying to kill urbs located in hif_dev->tx.tx_buf because hif_dev->tx.tx_buf is not supposed to contain urbs which are in pending state (the pending urbs are stored in hif_dev->tx.tx_pending). The tx.tx_lock is acquired so there should not be any changes in the list. Found by Linux Verification Center (linuxtesting.org) with Syzkaller.
Affected products
- Linux Linux: from 4.9.241, before 4.9.337 (fixed in 4.9.337); from 4.14.203, before 4.14.303 (fixed in 4.14.303); from 4.19.154, before 4.19.270 (fixed in 4.19.270); from 5.4.73, before 5.4.229 (fixed in 5.4.229); from 4.4.241, before 4.5 (fixed in 4.5); from 5.8.17, before 5.9 (fixed in 5.9); …
Published 2025-12-24. Last modified 2026-06-17.