CVE-2022-49298

Source
https://cve.org/CVERecord?id=CVE-2022-49298
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-49298.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2022-49298
Downstream
Related
Published
2025-02-26T02:01:27.111Z
Modified
2026-04-11T12:43:51.819018Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
staging: rtl8712: fix uninit-value in r871xu_drv_init()
Details

In the Linux kernel, the following vulnerability has been resolved:

staging: rtl8712: fix uninit-value in r871xudrvinit()

When 'tmpU1b' returns from r8712read8(padapter, EE9346CR) is 0, 'mac[6]' will not be initialized.

BUG: KMSAN: uninit-value in r871xudrvinit+0x2d54/0x3070 drivers/staging/rtl8712/usbintf.c:541 r871xudrvinit+0x2d54/0x3070 drivers/staging/rtl8712/usbintf.c:541 usbprobeinterface+0xf19/0x1600 drivers/usb/core/driver.c:396 really_probe+0x653/0x14b0 drivers/base/dd.c:596 __driverprobedevice+0x3e9/0x530 drivers/base/dd.c:752 driverprobedevice drivers/base/dd.c:782 [inline] __deviceattachdriver+0x79f/0x1120 drivers/base/dd.c:899 bus_foreachdrv+0x2d6/0x3f0 drivers/base/bus.c:427 __deviceattach+0x593/0x8e0 drivers/base/dd.c:970 deviceinitialprobe+0x4a/0x60 drivers/base/dd.c:1017 busprobedevice+0x17b/0x3e0 drivers/base/bus.c:487 deviceadd+0x1fff/0x26e0 drivers/base/core.c:3405 usbsetconfiguration+0x37e9/0x3ed0 drivers/usb/core/message.c:2170 usbgenericdriverprobe+0x13c/0x300 drivers/usb/core/generic.c:238 usbprobedevice+0x309/0x570 drivers/usb/core/driver.c:293 reallyprobe+0x653/0x14b0 drivers/base/dd.c:596 __driverprobedevice+0x3e9/0x530 drivers/base/dd.c:752 driverprobedevice drivers/base/dd.c:782 [inline] __deviceattachdriver+0x79f/0x1120 drivers/base/dd.c:899 bus_foreachdrv+0x2d6/0x3f0 drivers/base/bus.c:427 __deviceattach+0x593/0x8e0 drivers/base/dd.c:970 deviceinitialprobe+0x4a/0x60 drivers/base/dd.c:1017 busprobedevice+0x17b/0x3e0 drivers/base/bus.c:487 deviceadd+0x1fff/0x26e0 drivers/base/core.c:3405 usbnewdevice+0x1b8e/0x2950 drivers/usb/core/hub.c:2566 hubportconnect drivers/usb/core/hub.c:5358 [inline] hubportconnectchange drivers/usb/core/hub.c:5502 [inline] portevent drivers/usb/core/hub.c:5660 [inline] hubevent+0x58e3/0x89e0 drivers/usb/core/hub.c:5742 processonework+0xdb6/0x1820 kernel/workqueue.c:2307 workerthread+0x10b3/0x21e0 kernel/workqueue.c:2454 kthread+0x3c7/0x500 kernel/kthread.c:377 retfromfork+0x1f/0x30

Local variable mac created at: r871xudrvinit+0x1771/0x3070 drivers/staging/rtl8712/usbintf.c:394 usbprobe_interface+0xf19/0x1600 drivers/usb/core/driver.c:396

KMSAN: uninit-value in r871xudrvinit https://syzkaller.appspot.com/bug?id=3cd92b1d85428b128503bfa7a250294c9ae00bd8

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/49xxx/CVE-2022-49298.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
2865d42c78a9121caad52cb02d1fbb7f5cdbc4ef
Fixed
0b7371a22489cbb2e8e826ca03fb5ce92afb04fe
Fixed
277faa442fe0c59f418ac53f47a78e1266addd65
Fixed
a6535d00a9d54ce1c2a8d86a85001ffb6844f9b2
Fixed
52a0d88c328098b4e9fb8f2f3877fec0eff4104b
Fixed
ff727ab0b7d7a56b5ef281f12abd00c4b85894e9
Fixed
f36e754a1f0bafb9feeea63463de78080acb6de0
Fixed
76a964ad0ea8f2b10abd69a7532e174a28258283
Fixed
70df04433fd351ba72bc635bd0b5fe443d9ac964
Fixed
0458e5428e5e959d201a40ffe71d762a79ecedc4

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-49298.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.6.37
Fixed
4.9.318
Type
ECOSYSTEM
Events
Introduced
4.10.0
Fixed
4.14.283
Type
ECOSYSTEM
Events
Introduced
4.15.0
Fixed
4.19.247
Type
ECOSYSTEM
Events
Introduced
4.20.0
Fixed
5.4.198
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.122
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.47
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
5.17.15
Type
ECOSYSTEM
Events
Introduced
5.18.0
Fixed
5.18.4

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-49298.json"