LiveActive security incident?Get immediate response
CVE Record

CVE-2022-49479: mt76: fix tx status related use-after-free race on station removal

In the Linux kernel, the following vulnerability has been resolved: mt76: fix tx status related use-after-free race on station removal There is a small race window where ongoing tx activity can lead to a skb getting added to the status tracking idr after that idr has already been cleaned up, which will keep the wcid linked in the status poll list. Fix this by only adding status skbs if the wcid pointer is still assigned in dev->wcid, which gets cleared early by mt76_sta_pre_rcu_remove

HighCVSS 7.8Not KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

CVE-2022-49479 is a Linux kernel mt76 wireless driver race condition. During station removal, transmit-status tracking can keep using freed memory. On systems with the affected driver and kernel, a local low-privileged user could potentially cause serious confidentiality, integrity, or availability impact.

Executive priority

Treat as high priority for Linux fleets using affected wireless drivers, especially laptops, workstations, and shared systems. It is not presented as remotely exploitable in the supplied sources, but kernel memory-corruption impact warrants prompt patch tracking.

Technical view

The issue is a CWE-416 use-after-free in mt76 transmit status handling. The fix prevents status SKBs from being added after the WCID was cleared from dev->wcid during mt76_sta_pre_rcu_remove. CVSS 3.1 is 7.8, local attack vector, low complexity, low privileges, no user interaction.

Likely exposure

Exposure is most likely on Linux systems running affected kernel versions with mt76 MediaTek wireless driver support in use. Systems without the mt76 driver or relevant wireless hardware are less likely to be exposed, but kernel and module inventories are needed.

Exploitation context

The CVE record does not identify active exploitation, and KEV status is false in the supplied bundle. The CVSS vector indicates local access is required. Public sources provided do not include exploit details or proof-of-concept status.

Researcher notes

The supplied description points to a race between TX status tracking and station removal cleanup. Analysis should focus on mt76 WCID lifecycle, status poll list handling, and whether downstream kernels carry equivalent stable fixes.

Mitigation direction

  • Update to a vendor kernel containing the referenced stable fixes.
  • Check distribution advisories for backported mt76 patches.
  • Prioritize systems using MediaTek mt76 wireless devices.
  • If patch timing is unclear, follow vendor guidance for temporary risk reduction.

Validation and detection

  • Inventory kernel versions across Linux endpoints and appliances.
  • Check whether mt76 modules are present or loaded.
  • Confirm vendor packages include the referenced stable commits or equivalent backports.
  • Review wireless-capable systems first, especially shared or multi-user hosts.
Prepared
Confidence
medium
Sources
5

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · low confidence lookup

CWE-416: Exact CWE lookup

Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2022-49479 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
High
CVSS
7.8 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
3Timeline events
1ADP providers
4Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: noTechnical Impact: total

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
7.8CVSS 3.1HighCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H1.85.9CISA-ADP

Vulnerability scoring details

Base CVSS 3.1 score

7.8High
CVSS 3.1 vector shape for CVE-2022-49479Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
cvssV3_1other:ssvc
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
LinuxLinuxbd1e3e7b693c17a04e7d2bd9119daa482b7c7720, bd1e3e7b693c17a04e7d2bd9119daa482b7c7720, bd1e3e7b693c17a04e7d2bd9119daa482b7c7720unaffected
LinuxLinux5.16, 0, 5.17.14, 5.18.3, 5.19affected
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-416 · source CWE mapping

Use After Free

Use After Free represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.