CVE-2022-50852
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2022-50852 is a use-after-free vulnerability in the Linux kernel's Wi-Fi driver for MediaTek MT7921 chipsets, specifically within the mt7921_acpi_read() function in the mt76 driver subsystem. The flaw occurs when the sar_root pointer is dereferenced after the associated memory has already been freed. It was published on December 30, 2025, and affects Linux kernel versions in the range introduced by commit f965333e491e36adb0fa91e389fba8685b704fb6, with fixes landing in kernel 6.0.3 and 6.1. Feedly estimates the severity as Medium, with an EPSS score of approximately 0.018% (Feedly).

Technical details

The root cause is a use-after-free (CWE-416) in the mt7921_acpi_read() function of the mt76 MT7921 Wi-Fi driver. After a memory buffer associated with sar_root is freed, the code continues to dereference that pointer, leading to undefined behavior — typically a kernel crash or potential memory corruption. Exploitation would require local access to a system with an affected MT7921 Wi-Fi chipset and the ability to trigger the ACPI read path. Fixes were committed to the stable kernel tree at commits 3ed0b382cb36f6dac9f93b3a5533cfcd699409a5 and e7de4b4979bd8d313ec837931dde936653ca82ea (Kernel Git, Kernel Git).

Impact

Successful exploitation of this use-after-free vulnerability could result in a kernel panic (denial of service) or, in more sophisticated scenarios, memory corruption that could be leveraged for privilege escalation on the local system. The vulnerability is confined to systems running the affected Linux kernel versions with MediaTek MT7921 Wi-Fi hardware. There is no indication of network-based exploitation or lateral movement potential, as the attack surface is limited to local kernel driver interaction (Feedly).

Mitigation and workarounds

The fix has been merged into the Linux stable kernel tree. Users should update to Linux kernel version 6.0.3 or later (for the 6.0.x branch) or kernel 6.1 or later, which include the corrective commits (3ed0b382cb36 and e7de4b4979bd). Linux distribution maintainers (e.g., Debian, Ubuntu, RHEL) may backport this fix to their supported kernel versions; users should apply the latest kernel updates provided by their distribution. As a temporary workaround, systems without MT7921 Wi-Fi hardware are not affected, and the mt7921 kernel module can be blocklisted on systems that do not require it (Kernel Git, Kernel Git).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64557NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-selftests-internal
NoNoJul 29, 2026
CVE-2026-64556NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-devel
NoNoJul 29, 2026
CVE-2026-64555NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-fde-6.14
NoNoJul 27, 2026
CVE-2026-64554NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-gcp-6.14
NoYesJul 27, 2026
CVE-2026-64553NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-64k-debug-modules-internal
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management