LiveActive security incident?Get immediate response
CVE Record

CVE-2022-50551: wifi: brcmfmac: Fix potential shift-out-of-bounds in brcmf_fw_alloc_request()

In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: Fix potential shift-out-of-bounds in brcmf_fw_alloc_request() This patch fixes a shift-out-of-bounds in brcmfmac that occurs in BIT(chiprev) when a 'chiprev' provided by the device is too large. It should also not be equal to or greater than BITS_PER_TYPE(u32) as we do bitwise AND with a u32 variable and BIT(chiprev). The patch adds a check that makes the function return NULL if that is the case. Note that the NULL case is later handled by the bus-specific caller, brcmf_usb_probe_cb() or brcmf_usb_reset_resume(), for example. Found by a modified version of syzkaller. UBSAN: shift-out-of-bounds in drivers/net/wireless/broadcom/brcm80211/brcmfmac/firmware.c shift exponent 151055786 is too large for 64-bit type 'long unsigned int' CPU: 0 PID: 1885 Comm: kworker/0:2 Tainted: G O 5.14.0+ #132 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.12.1-0-ga5cab58e9a3f-prebuilt.qemu.org 04/01/2014 Workqueue: usb_hub_wq hub_event Call Trace: dump_stack_lvl+0x57/0x7d ubsan_epilogue+0x5/0x40 __ubsan_handle_shift_out_of_bounds.cold+0x53/0xdb ? lock_chain_count+0x20/0x20 brcmf_fw_alloc_request.cold+0x19/0x3ea ? brcmf_fw_get_firmwares+0x250/0x250 ? brcmf_usb_ioctl_resp_wait+0x1a7/0x1f0 brcmf_usb_get_fwname+0x114/0x1a0 ? brcmf_usb_reset_resume+0x120/0x120 ? number+0x6c4/0x9a0 brcmf_c_process_clm_blob+0x168/0x590 ? put_dec+0x90/0x90 ? enable_ptr_key_workfn+0x20/0x20 ? brcmf_common_pd_remove+0x50/0x50 ? rcu_read_lock_sched_held+0xa1/0xd0 brcmf_c_preinit_dcmds+0x673/0xc40 ? brcmf_c_set_joinpref_default+0x100/0x100 ? rcu_read_lock_sched_held+0xa1/0xd0 ? rcu_read_lock_bh_held+0xb0/0xb0 ? lock_acquire+0x19d/0x4e0 ? find_held_lock+0x2d/0x110 ? brcmf_usb_deq+0x1cc/0x260 ? mark_held_locks+0x9f/0xe0 ? lockdep_hardirqs_on_prepare+0x273/0x3e0 ? _raw_spin_unlock_irqrestore+0x47/0x50 ? trace_hardirqs_on+0x1c/0x120 ? brcmf_usb_deq+0x1a7/0x260 ? brcmf_usb_rx_fill_all+0x5a/0xf0 brcmf_attach+0x246/0xd40 ? wiphy_new_nm+0x1476/0x1d50 ? kmemdup+0x30/0x40 brcmf_usb_probe+0x12de/0x1690 ? brcmf_usbdev_qinit.constprop.0+0x470/0x470 usb_probe_interface+0x25f/0x710 really_probe+0x1be/0xa90 __driver_probe_device+0x2ab/0x460 ? usb_match_id.part.0+0x88/0xc0 driver_probe_device+0x49/0x120 __device_attach_driver+0x18a/0x250 ? driver_allows_async_probing+0x120/0x120 bus_for_each_drv+0x123/0x1a0 ? bus_rescan_devices+0x20/0x20 ? lockdep_hardirqs_on_prepare+0x273/0x3e0 ? trace_hardirqs_on+0x1c/0x120 __device_attach+0x207/0x330 ? device_bind_driver+0xb0/0xb0 ? kobject_uevent_env+0x230/0x12c0 bus_probe_device+0x1a2/0x260 device_add+0xa61/0x1ce0 ? __mutex_unlock_slowpath+0xe7/0x660 ? __fw_devlink_link_to_suppliers+0x550/0x550 usb_set_configuration+0x984/0x1770 ? kernfs_create_link+0x175/0x230 usb_generic_driver_probe+0x69/0x90 usb_probe_device+0x9c/0x220 really_probe+0x1be/0xa90 __driver_probe_device+0x2ab/0x460 driver_probe_device+0x49/0x120 __device_attach_driver+0x18a/0x250 ? driver_allows_async_probing+0x120/0x120 bus_for_each_drv+0x123/0x1a0 ? bus_rescan_devices+0x20/0x20 ? lockdep_hardirqs_on_prepare+0x273/0x3e0 ? trace_hardirqs_on+0x1c/0x120 __device_attach+0x207/0x330 ? device_bind_driver+0xb0/0xb0 ? kobject_uevent_env+0x230/0x12c0 bus_probe_device+0x1a2/0x260 device_add+0xa61/0x1ce0 ? __fw_devlink_link_to_suppliers+0x550/0x550 usb_new_device.cold+0x463/0xf66 ? hub_disconnect+0x400/0x400 ? _raw_spin_unlock_irq+0x24/0x30 hub_event+0x10d5/0x3330 ? hub_port_debounce+0x280/0x280 ? __lock_acquire+0x1671/0x5790 ? wq_calc_node_cpumask+0x170/0x2a0 ? lock_release+0x640/0x640 ? rcu_read_lock_sched_held+0xa1/0xd0 ? rcu_read_lock_bh_held+0xb0/0xb0 ? lockdep_hardirqs_on_prepare+0x273/0x3e0 process_one_work+0x873/0x13e0 ? lock_release+0x640/0x640 ? pwq_dec_nr_in_flight+0x320/0x320 ? rwlock_bug.part.0+0x90/0x90 worker_thread+0x8b/0xd10 ? __kthread_parkme+0xd9/0x1d0 ? pr ---truncated---

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysislow

Security readout for executives and security teams

Plain-English summary

A bug in the Linux kernel's Broadcom Wi-Fi driver could crash a system when a malformed or malicious USB Wi-Fi adapter is plugged in. The issue is a math error triggered by a bad value the device reports, and it has been fixed in current kernels. Risk centers on systems where someone can attach untrusted USB Wi-Fi hardware.

Executive priority

Low priority for most enterprises. Patch as part of routine Linux kernel updates. Treat as higher priority for fleets that allow user-supplied USB Wi-Fi adapters, kiosks, lab benches, or embedded Linux devices that ship with Broadcom Wi-Fi over USB.

Technical view

CVE-2022-50551 is a shift-out-of-bounds in brcmf_fw_alloc_request() in drivers/net/wireless/broadcom/brcm80211/brcmfmac/firmware.c. When a USB Broadcom Wi-Fi device reports a chiprev that is too large for BIT(chiprev) on a u32, undefined behavior occurs. The patch returns NULL when chiprev is out of range, and callers like brcmf_usb_probe_cb() handle the NULL. Found via a modified syzkaller fuzzer.

Likely exposure

Affects Linux kernels before 4.9.337, 4.14.303/305, 4.19.270, 5.4.229, 5.10.163, 5.15.86, 6.0.16, 6.1.2, and pre-6.2 that use the brcmfmac driver with USB-attached Broadcom Wi-Fi devices. Exposure is highest where untrusted USB hardware can be physically connected; remote exposure is not indicated by sources.

Exploitation context

No public reports of in-the-wild exploitation. Not in CISA KEV. The flaw was discovered by a syzkaller-based fuzzer and triggers UBSAN; the immediate observed effect is undefined behavior in the kernel during USB Wi-Fi device probe. Trigger requires a device that returns an oversized chiprev value, implying physical or supply-chain access to the USB adapter.

Researcher notes

CVSS, severity, and CWE are not provided in the source bundle. Affected version data lists multiple stable branches with explicit fixed points, indicating a backport-heavy resolution. Trigger path begins at usb_probe_interface and reaches brcmf_fw_alloc_request via brcmf_usb_probe and brcmf_attach. The fix is a defensive bounds check; no evidence of memory corruption or privilege escalation primitive is described in the bundle. Reporter tooling: modified syzkaller.

Mitigation direction

  • Apply distribution kernel updates that include the brcmfmac fix for your branch (4.9.337+, 4.14.303+, 4.19.270+, 5.4.229+, 5.10.163+, 5.15.86+, 6.0.16+, 6.1.2+, or 6.2+).
  • Restrict who can attach unknown USB Wi-Fi adapters to managed Linux endpoints, servers, and embedded devices.
  • On systems that do not need Broadcom Wi-Fi, blacklist the brcmfmac module to remove the attack surface.
  • For embedded or IoT fleets, confirm vendor firmware images include a kernel rebased past the patched stable point releases.
  • Track vendor advisories (distribution security trackers) for backports specific to your kernel build.

Validation and detection

  • Run 'uname -r' and compare against the fixed stable versions listed in the kernel.org commits.
  • Check whether brcmfmac is loaded with 'lsmod | grep brcmfmac' and inventory hosts that load it.
  • Review distribution security trackers (Debian, Ubuntu, SUSE, Red Hat) for CVE-2022-50551 status against your installed kernel package.
  • On test systems, watch dmesg for 'UBSAN: shift-out-of-bounds' messages referencing brcmfmac/firmware.c when attaching USB Wi-Fi devices.
  • Confirm the upstream commits referenced in the CVE record are present in your kernel source tree if you build kernels in-house.
Prepared
Confidence
medium
Sources
12

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2022-50551 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
11Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
LinuxLinux46d703a775394e4724509ff55cdda41d228c028c, 46d703a775394e4724509ff55cdda41d228c028c, 46d703a775394e4724509ff55cdda41d228c028c, 46d703a775394e4724509ff55cdda41d228c028c, 46d703a775394e4724509ff55cdda41d228c028c, 46d703a775394e4724509ff55cdda41d228c028c, 46d703a775394e4724509ff55cdda41d228c028c, 46d703a775394e4724509ff55cdda41d228c028c, 46d703a775394e4724509ff55cdda41d228c028c, 46d703a775394e4724509ff55cdda41d228c028cunaffected
LinuxLinux4.5, 0, 4.9.337, 4.14.303, 4.14.305, 4.19.270, 5.4.229, 5.10.163, 5.15.86, 6.0.16, 6.1.2, 6.2affected
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.