CVE-2022-50164: wifi: iwlwifi: mvm: fix double list_add at iwl_mvm_mac_wake_tx_queue

Published Jun 18, 2025
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

wifi: iwlwifi: mvm: fix double listadd at iwlmvmmacwaketxqueue

After successfull station association, if station queues are disabled for some reason, the related lists are not emptied. So if some new element is added to the list in iwlmvmmacwaketxqueue, it can match with the old one and produce a BUG like this:

[ 46.535263] listadd corruption. prev->next should be next (ffff94c1c318a360), but was 0000000000000000. (prev=ffff94c1d02d3388). [ 46.535283] ------------[ cut here ]------------ [ 46.535284] kernel BUG at lib/listdebug.c:26! [ 46.535290] invalid opcode: 0000 [#1] PREEMPT SMP PTI [ 46.585304] CPU: 0 PID: 623 Comm: wpasupplicant Not tainted 5.19.0-rc3+ #1 [ 46.592380] Hardware name: Dell Inc. Inspiron 660s/0478VN , BIOS A07 08/24/2012 [ 46.600336] RIP: 0010:listaddvalid.cold+0x3d/0x3f [ 46.605475] Code: f2 4c 89 c1 48 89 fe 48 c7 c7 c8 40 67 93 e8 20 cc fd ff 0f 0b 48 89 d1 4c 89 c6 4c 89 ca 48 c7 c7 70 40 67 93 e8 09 cc fd ff <0f> 0b 48 89 fe 48 c7 c7 00 41 67 93 e8 f8 cb fd ff 0f 0b 48 89 d1 [ 46.624469] RSP: 0018:ffffb20800ab76d8 EFLAGS: 00010286 [ 46.629854] RAX: 0000000000000075 RBX: ffff94c1c318a0e0 RCX: 0000000000000000 [ 46.637105] RDX: 0000000000000201 RSI: ffffffff9365e100 RDI: 00000000ffffffff [ 46.644356] RBP: ffff94c1c5f43370 R08: 0000000000000075 R09: 3064316334396666 [ 46.651607] R10: 3364323064316334 R11: 39666666663d7665 R12: ffff94c1c5f43388 [ 46.658857] R13: ffff94c1d02d3388 R14: ffff94c1c318a360 R15: ffff94c1cf2289c0 [ 46.666108] FS: 00007f65634ff7c0(0000) GS:ffff94c1da200000(0000) knlGS:0000000000000000 [ 46.674331] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 46.680170] CR2: 00007f7dfe984460 CR3: 000000010e894003 CR4: 00000000000606f0 [ 46.687422] Call Trace: [ 46.689906] <TASK> [ 46.691950] iwlmvmmacwaketxqueue+0xec/0x15c [iwlmvm] [ 46.697601] ieee80211queueskb+0x4b3/0x720 [mac80211] [ 46.702973] ? stainfoget+0x46/0x60 [mac80211] [ 46.707703] ieee80211tx+0xad/0x110 [mac80211] [ 46.712355] ieee80211txskbtidband+0x71/0x90 [mac80211] ...

In order to avoid this problem, we must also remove the related lists when station queues are disabled.

Affected Software

6 affected components
Linux Kernel
Linux Linux kernel>=5.1<5.4.211
Linux Linux kernel>=5.5<5.10.137
Linux Linux kernel>=5.11<5.15.61
Linux Linux kernel>=5.16<5.18.18
Linux Linux kernel>=5.19<5.19.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Linux kernel (iwlwifi/mact80211 path) to a version that resolves this vulnerability.

    Patch wifi: iwlwifi: mvm: fix double list_add at iwl_mvm_mac_wake_tx_queue
  2. Configuration

    If station queues are disabled (as described), ensure the related lists are emptied/removed as required to prevent double list_add in iwl_mvm_mac_wake_tx_queue.

    mac80211 station queues (when disabling station queues) station queues = disabled

Event History

Jun 18, 2025
CVE Published
via MITRE·11:03 AM
Data Sourced
via MITRE·11:03 AM
DescriptionSeverity
Data Sourced
via NVD·11:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Nov 23, 58560
Event
via MITRE·08:53 AM

Frequently Asked Questions

1

What is the severity of CVE-2022-50164?

CVE-2022-50164 is classified as a medium severity vulnerability affecting the Linux kernel.

2

How do I fix CVE-2022-50164?

To fix CVE-2022-50164, you should update to the latest version of the Linux kernel that addresses this vulnerability.

3

What software is affected by CVE-2022-50164?

CVE-2022-50164 affects systems running certain versions of the Linux kernel, specifically those utilizing the iwlwifi driver.

4

What exploit is associated with CVE-2022-50164?

CVE-2022-50164 does not have a publicly known exploit but can potentially lead to unexpected behavior in affected systems.

5

How was CVE-2022-50164 discovered?

CVE-2022-50164 was discovered during routine analysis of the Linux kernel's iwlwifi driver functionality.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203