CVE-2022-50164: wifi: iwlwifi: mvm: fix double list_add at iwl_mvm_mac_wake_tx_queue
In the Linux kernel, the following vulnerability has been resolved:
wifi: iwlwifi: mvm: fix double listadd at iwlmvmmacwaketxqueue
After successfull station association, if station queues are disabled for some reason, the related lists are not emptied. So if some new element is added to the list in iwlmvmmacwaketxqueue, it can match with the old one and produce a BUG like this:
[ 46.535263] listadd corruption. prev->next should be next (ffff94c1c318a360), but was 0000000000000000. (prev=ffff94c1d02d3388). [ 46.535283] ------------[ cut here ]------------ [ 46.535284] kernel BUG at lib/listdebug.c:26! [ 46.535290] invalid opcode: 0000 [#1] PREEMPT SMP PTI [ 46.585304] CPU: 0 PID: 623 Comm: wpasupplicant Not tainted 5.19.0-rc3+ #1 [ 46.592380] Hardware name: Dell Inc. Inspiron 660s/0478VN , BIOS A07 08/24/2012 [ 46.600336] RIP: 0010:listaddvalid.cold+0x3d/0x3f [ 46.605475] Code: f2 4c 89 c1 48 89 fe 48 c7 c7 c8 40 67 93 e8 20 cc fd ff 0f 0b 48 89 d1 4c 89 c6 4c 89 ca 48 c7 c7 70 40 67 93 e8 09 cc fd ff <0f> 0b 48 89 fe 48 c7 c7 00 41 67 93 e8 f8 cb fd ff 0f 0b 48 89 d1 [ 46.624469] RSP: 0018:ffffb20800ab76d8 EFLAGS: 00010286 [ 46.629854] RAX: 0000000000000075 RBX: ffff94c1c318a0e0 RCX: 0000000000000000 [ 46.637105] RDX: 0000000000000201 RSI: ffffffff9365e100 RDI: 00000000ffffffff [ 46.644356] RBP: ffff94c1c5f43370 R08: 0000000000000075 R09: 3064316334396666 [ 46.651607] R10: 3364323064316334 R11: 39666666663d7665 R12: ffff94c1c5f43388 [ 46.658857] R13: ffff94c1d02d3388 R14: ffff94c1c318a360 R15: ffff94c1cf2289c0 [ 46.666108] FS: 00007f65634ff7c0(0000) GS:ffff94c1da200000(0000) knlGS:0000000000000000 [ 46.674331] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 46.680170] CR2: 00007f7dfe984460 CR3: 000000010e894003 CR4: 00000000000606f0 [ 46.687422] Call Trace: [ 46.689906] <TASK> [ 46.691950] iwlmvmmacwaketxqueue+0xec/0x15c [iwlmvm] [ 46.697601] ieee80211queueskb+0x4b3/0x720 [mac80211] [ 46.702973] ? stainfoget+0x46/0x60 [mac80211] [ 46.707703] ieee80211tx+0xad/0x110 [mac80211] [ 46.712355] ieee80211txskbtidband+0x71/0x90 [mac80211] ...
In order to avoid this problem, we must also remove the related lists when station queues are disabled.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Linux kernel (iwlwifi/mact80211 path)to a version that resolves this vulnerability.Patch wifi: iwlwifi: mvm: fix double list_add at iwl_mvm_mac_wake_tx_queue - Configuration
If station queues are disabled (as described), ensure the related lists are emptied/removed as required to prevent double list_add in iwl_mvm_mac_wake_tx_queue.
mac80211 station queues (when disabling station queues) station queues = disabled
Event History
Frequently Asked Questions
What is the severity of CVE-2022-50164?
CVE-2022-50164 is classified as a medium severity vulnerability affecting the Linux kernel.
How do I fix CVE-2022-50164?
To fix CVE-2022-50164, you should update to the latest version of the Linux kernel that addresses this vulnerability.
What software is affected by CVE-2022-50164?
CVE-2022-50164 affects systems running certain versions of the Linux kernel, specifically those utilizing the iwlwifi driver.
What exploit is associated with CVE-2022-50164?
CVE-2022-50164 does not have a publicly known exploit but can potentially lead to unexpected behavior in affected systems.
How was CVE-2022-50164 discovered?
CVE-2022-50164 was discovered during routine analysis of the Linux kernel's iwlwifi driver functionality.