Security readout for executives and security teams
Plain-English summary
CVE-2022-50852 is a Linux kernel bug in the MediaTek MT7921 Wi-Fi driver. The driver could access memory after it was freed during an ACPI read path. Public sources provide no CVSS score, no confirmed exploitation, and limited impact detail, so urgency depends on whether affected kernels and hardware are present.
Executive priority
Moderate operational priority for organizations with Linux laptops or endpoints using MediaTek MT7921 Wi-Fi. Lower priority for environments without that hardware. Because severity and exploitation evidence are missing, focus on routine kernel patching and targeted validation rather than emergency response.
Technical view
The issue is a use-after-free in mt76/mt7921, specifically mt7921_acpi_read(), where sar_root was dereferenced after being freed. The CVE lists Linux kernel versions including 6.0 through 6.0.3 and 6.1 as affected, with fixes referenced in stable kernel commits.
Likely exposure
Exposure is likely limited to Linux systems using the MediaTek MT7921 Wi-Fi driver on affected kernel versions. Servers without this Wi-Fi hardware or driver are likely not exposed, but confirm by asset and kernel inventory.
Exploitation context
The source bundle does not report active exploitation, public exploit availability, or KEV listing. Impact details are not provided beyond a kernel use-after-free, so treat this as a stability and potential security issue pending vendor-specific guidance.
Researcher notes
Public data is sparse: no CVSS, CWE, detailed impact, or exploitability analysis is included. The useful anchors are the kernel commit messages and affected version ranges. Further assessment should compare downstream distro backports against the two referenced stable commits.
Mitigation direction
- Update to a Linux kernel or vendor package containing the referenced stable fixes.
- Check your Linux distribution’s security advisory for CVE-2022-50852 coverage.
- Prioritize systems with MediaTek MT7921 Wi-Fi hardware and affected kernels.
- If updates are unavailable, follow vendor guidance for temporary risk reduction.
Validation and detection
- Inventory Linux kernel versions across endpoints and laptops.
- Identify systems with MediaTek MT7921 Wi-Fi hardware or mt7921 driver usage.
- Confirm installed kernels include the referenced stable commits or distro backports.
- Review vendor advisories for affected package versions and fixed builds.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2022-50852 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
