CVE-2022-50627: wifi: ath11k: fix monitor mode bringup crash

Published Dec 8, 2025
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

wifi: ath11k: fix monitor mode bringup crash

When the interface is brought up in monitor mode, it leads to NULL pointer dereference crash. This crash happens when the packet type is extracted for a SKB. This extraction which is present in the received msdu delivery path,is not needed for the monitor ring packets since they are all RAW packets. Hence appending the flags with "RXFLAGONLYMONITOR" to skip that extraction.

Observed calltrace:

Unable to handle kernel NULL pointer dereference at virtual address 0000000000000064 Mem abort info: ESR = 0x0000000096000004 EC = 0x25: DABT (current EL), IL = 32 bits SET = 0, FnV = 0 EA = 0, S1PTW = 0 FSC = 0x04: level 0 translation fault Data abort info: ISV = 0, ISS = 0x00000004 CM = 0, WnR = 0 user pgtable: 4k pages, 48-bit VAs, pgdp=0000000048517000 [0000000000000064] pgd=0000000000000000, p4d=0000000000000000 Internal error: Oops: 0000000096000004 [#1] PREEMPT SMP Modules linked in: ath11kpci ath11k qmihelpers CPU: 2 PID: 1781 Comm: napi/-271 Not tainted 6.1.0-rc5-wt-ath-656295-gef907406320c-dirty #6 Hardware name: Qualcomm Technologies, Inc. IPQ8074/AP-HK10-C2 (DT) pstate: 60000005 (nZCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--) pc : ath11khwqcn9074rxdescgetdecaptype+0x34/0x60 [ath11k] lr : ath11khwqcn9074rxdescgetdecaptype+0x5c/0x60 [ath11k] sp : ffff80000ef5bb10 x29: ffff80000ef5bb10 x28: 0000000000000000 x27: ffff000007baafa0 x26: ffff000014a91ed0 x25: 0000000000000000 x24: 0000000000000000 x23: ffff800002b77378 x22: ffff000014a91ec0 x21: ffff000006c8d600 x20: 0000000000000000 x19: ffff800002b77740 x18: 0000000000000006 x17: 736564203634343a x16: 656e694c20657079 x15: 0000000000000143 x14: 00000000ffffffea x13: ffff80000ef5b8b8 x12: ffff80000ef5b8c8 x11: ffff80000a591d30 x10: ffff80000a579d40 x9 : c0000000ffffefff x8 : 0000000000000003 x7 : 0000000000017fe8 x6 : ffff80000a579ce8 x5 : 0000000000000000 x4 : 0000000000000000 x3 : 0000000000000000 x2 : 3a35ec12ed7f8900 x1 : 0000000000000000 x0 : 0000000000000052 Call trace: ath11khwqcn9074rxdescgetdecaptype+0x34/0x60 [ath11k] ath11kdprxdelivermsdu.isra.42+0xa4/0x3d0 [ath11k] ath11kdprxmondeliver.isra.43+0x2f8/0x458 [ath11k] ath11kdprxprocessmonrings+0x310/0x4c0 [ath11k] ath11kdpservicesrng+0x234/0x338 [ath11k] ath11kpcicextgrpnapipoll+0x30/0xb8 [ath11k] napipoll+0x5c/0x190 napithreadedpoll+0xf0/0x118 kthread+0xf4/0x110 retfromfork+0x10/0x20

Tested-on: QCN9074 hw1.0 PCI WLAN.HK.2.7.0.1-01744-QCAHKSWPLSILICONZ-1

Affected Software

1 affected component
Linux Linux kernel (ath11k)

Event History

Dec 8, 2025
CVE Published
via MITRE·01:16 AM
Data Sourced
via MITRE·01:16 AM
Description
Data Sourced
via NVD·02:15 AM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2022-50627?

CVE-2022-50627 is classified as a high severity vulnerability due to the potential for a denial of service attack resulting from a NULL pointer dereference.

2

How do I fix CVE-2022-50627?

To fix CVE-2022-50627, it is recommended to upgrade to the latest patched version of the Linux Kernel that addresses this issue.

3

Which Linux Kernel versions are affected by CVE-2022-50627?

CVE-2022-50627 affects multiple versions of the Linux Kernel where the ath11k wireless driver is used.

4

What are the potential impacts of CVE-2022-50627?

The potential impacts of CVE-2022-50627 include system crashes and interruptions in network functionality when using monitor mode.

5

Is CVE-2022-50627 a remote vulnerability?

CVE-2022-50627 is not a remote vulnerability; it requires local access to the system to exploit the monitor mode functionality.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203