CVE-2022-50178: wifi: rtw89: 8852a: rfk: fix div 0 exception
In the Linux kernel, the following vulnerability has been resolved:
wifi: rtw89: 8852a: rfk: fix div 0 exception
The DPK is a kind of RF calibration whose algorithm is to fine tune
parameters and calibrate, and check the result. If the result isn't good
enough, it could adjust parameters and try again.
This issue is to read and show the result, but it could be a negative
calibration result that causes divisor 0 and core dump. So, fix it by
phy_div() that does division only if divisor isn't zero; otherwise,
zero is adopted.
divide error: 0000 [#1] PREEMPT SMP NOPTI
CPU: 1 PID: 728 Comm: wpa_supplicant Not tainted 5.10.114-16019-g462a1661811a #1 <HASH:d024 28>
RIP: 0010:rtw8852a_dpk+0x14ae/0x288f [rtw89_core]
RSP: 0018:ffffa9bb412a7520 EFLAGS: 00010246
RAX: 0000000000000000 RBX: 0000000000000000 RCX: 0000000000000000
RDX: 0000000000000000 RSI: 00000000000180fc RDI: ffffa141d01023c0
RBP: ffffa9bb412a76a0 R08: 0000000000001319 R09: 00000000ffffff92
R10: ffffffffc0292de3 R11: ffffffffc00d2f51 R12: 0000000000000000
R13: ffffa141d01023c0 R14: ffffffffc0290250 R15: ffffa141d0102638
FS: 00007fa99f5c2740(0000) GS:ffffa142e5e80000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000013e8e010 CR3: 0000000110d2c000 CR4: 0000000000750ee0
PKRU: 55555554
Call Trace:
rtw89_core_sta_add+0x95/0x9c [rtw89_core <HASH:d239 29>]
rtw89_ops_sta_state+0x5d/0x108 [rtw89_core <HASH:d239 29>]
drv_sta_state+0x115/0x66f [mac80211 <HASH:81fe 30>]
sta_info_insert_rcu+0x45c/0x713 [mac80211 <HASH:81fe 30>]
sta_info_insert+0xf/0x1b [mac80211 <HASH:81fe 30>]
ieee80211_prep_connection+0x9d6/0xb0c [mac80211 <HASH:81fe 30>]
ieee80211_mgd_auth+0x2aa/0x352 [mac80211 <HASH:81fe 30>]
cfg80211_mlme_auth+0x160/0x1f6 [cfg80211 <HASH:00cd 31>]
nl80211_authenticate+0x2e5/0x306 [cfg80211 <HASH:00cd 31>]
genl_rcv_msg+0x371/0x3a1
? nl80211_stop_sched_scan+0xe5/0xe5 [cfg80211 <HASH:00cd 31>]
? genl_rcv+0x36/0x36
netlink_rcv_skb+0x8a/0xf9
genl_rcv+0x28/0x36
netlink_unicast+0x27b/0x3a0
netlink_sendmsg+0x2aa/0x469
sock_sendmsg_nosec+0x49/0x4d
____sys_sendmsg+0xe5/0x213
__sys_sendmsg+0xec/0x157
? syscall_enter_from_user_mode+0xd7/0x116
do_syscall_64+0x43/0x55
entry_SYSCALL_64_after_hwframe+0x44/0xa9
RIP: 0033:0x7fa99f6e689b
Security readout for executives and security teams
Plain-English summary
This Linux kernel issue can crash systems using the Realtek rtw89 8852A Wi-Fi driver when RF calibration results produce a zero divisor. The known impact from the sources is availability: a kernel divide error and core dump during Wi-Fi connection handling. There is no cited evidence of active exploitation.
Executive priority
Treat this as a targeted availability risk for Linux endpoints with specific Realtek Wi-Fi hardware. It does not currently justify emergency enterprise-wide action without matching hardware exposure, but affected fleets should receive normal kernel security updates promptly.
Technical view
The rtw89 8852A RF calibration path, specifically DPK result handling in rtw8852a_dpk, could divide by zero after a negative calibration result. The kernel fix replaces direct division with phy_div(), which returns zero when the divisor is zero. The crash trace involves wpa_supplicant, mac80211, cfg80211, and nl80211 authentication flow.
Likely exposure
Exposure is likely limited to Linux systems using the rtw89 driver with Realtek 8852A Wi-Fi hardware. Servers without this wireless chipset or driver are unlikely to be exposed. Distribution backports may change affected status, so package-level verification is required.
Exploitation context
The source describes a crash condition during Wi-Fi calibration and connection handling, not privilege escalation or code execution. KEV status is false, and the provided sources do not report public exploitation. Triggerability by nearby Wi-Fi conditions or normal connection activity is not fully established.
Researcher notes
Evidence is limited to the CVE record and kernel stable fixes. No CVSS, CWE, exploit maturity, or distro-specific fixed package data is included. The record’s affected version data is not enough to determine every downstream kernel exposure without vendor advisories.
Mitigation direction
Update to a kernel containing one of the referenced stable fixes.
Check Linux distribution advisories for backported rtw89 fixes.
Disable or avoid affected Realtek 8852A Wi-Fi hardware where updates are unavailable.
Prioritize laptops, workstations, and embedded devices using rtw89 Wi-Fi.
Monitor for recurring kernel divide errors in rtw89_core.
Validation and detection
Inventory systems for Realtek 8852A hardware and loaded rtw89 modules.
Compare running kernel packages against vendor fixed versions or backport notes.
Review kernel logs for rtw8852a_dpk divide errors or rtw89_core crashes.
Confirm the fix commit or equivalent patch is present in deployed kernels.
Validate Wi-Fi association no longer triggers kernel crashes after updating.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2022-50178 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
0CVSS vectors
3Timeline events
0ADP providers
4Source links
Vulnerability timeline
Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.
CVE reservedCVE Program
The CVE ID was reserved by the assigning CNA.
CVE publishedCVE Program
The CVE record was published.
Jun 18, 2025, 11:03 UTC (UTC+00:00)
CVE updatedCVE Program
The CVE record metadata indicates this as the latest update time.