CVE-2022-49539
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2022-49539 affects the Linux kernel's rtw89 wireless driver. The vulnerability involves CAM (Content Addressable Memory) leaks occurring during the System Error Recovery (SER) L2 reset process and ieee80211restarthw() operation. The issue was discovered in March 2022 and was fixed through kernel patches (Kernel Patch).

Technical details

The vulnerability occurs in the address CAM and BSSID CAM handling during system error recovery. The normal flow sequence that leads to the leak is: add interface (acquire 1) -> enter ips (release 1) -> leave ips (acquire 1) -> connection (occupy 1), resulting in one leak after L2 reset for non-secure connections. Additionally, during ieee80211restarthw() flow under connection, the sequence (ieee80211 reconfig -> add interface -> leave ips -> connection) causes another leak (Kernel Patch).

Impact

The vulnerability results in memory leaks in the Linux kernel's wireless networking subsystem, specifically affecting systems using the rtw89 wireless driver. These leaks occur during system error recovery processes and can potentially lead to resource exhaustion over time (Kernel Patch).

Mitigation and workarounds

The issue was fixed by modifying the CAM release behavior to release CAM regardless of connection security status, and by implementing checks to prevent multiple CAM acquisitions. For AP mode, the fix includes releasing address CAM of all stations before hardware restart (Kernel Patch).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-40343MEDIUM6.4
  • Linux KernelLinux Kernel
  • kernel-rt-modules-internal
NoYesDec 09, 2025
CVE-2025-40342MEDIUM6.4
  • Linux KernelLinux Kernel
  • kernel-debug-modules-extra
NoYesDec 09, 2025
CVE-2025-40341MEDIUM5.1
  • Linux KernelLinux Kernel
  • linux-nvidia-tegra
NoYesDec 09, 2025
CVE-2025-40345N/AN/A
  • Linux KernelLinux Kernel
  • kernel-headers
NoYesDec 12, 2025
CVE-2025-40344N/AN/A
  • Linux KernelLinux Kernel
  • linux-azure-6.14
NoYesDec 09, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management