CVE-2022-50321
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2022-50321 is a memory leak vulnerability discovered in the Linux kernel's brcmfmac WiFi driver component. The issue was identified in the brcmf_netdev_start_xmit() function, which returns NETDEV_TX_OK without properly freeing the skb (socket buffer) when pskb_expand_head() fails (NVD).

Technical details

The vulnerability exists in the brcmf_netdev_start_xmit() function of the Linux kernel's brcmfmac WiFi driver. When pskb_expand_head() fails, the function returns NETDEV_TX_OK without freeing the socket buffer (skb), leading to a potential memory leak. The fix involves adding dev_kfree_skb() to properly free the memory when the failure occurs (NVD).

Impact

The vulnerability can lead to memory leaks in the Linux kernel when using the brcmfmac WiFi driver. While it can lead to gradual resource exhaustion under repeated error conditions, the impact appears to be limited to memory resource consumption (Red Hat).

Mitigation and workarounds

The vulnerability has been patched in various Linux distributions. Ubuntu has released fixes for multiple versions including Ubuntu 22.04 LTS (5.15.0-75.82), 20.04 LTS (5.4.0-152.169), and various kernel variants for cloud platforms (Ubuntu). Users are advised to update their systems to the patched versions.

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-71142N/AN/A
  • Linux KernelLinux Kernel
  • bpftool
NoNoJan 14, 2026
CVE-2025-71137N/AN/A
  • Linux KernelLinux Kernel
  • linux-azure-nvidia-6.14
NoYesJan 14, 2026
CVE-2025-71135N/AN/A
  • Linux KernelLinux Kernel
  • linux-oracle-6.14
NoNoJan 14, 2026
CVE-2025-71134N/AN/A
  • Linux KernelLinux Kernel
  • kernel-zfcpdump-devel
NoNoJan 14, 2026
CVE-2025-71133N/AN/A
  • Linux KernelLinux Kernel
  • kernel-rt-debug-devel
NoYesJan 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management