Review reviewHigh

CVE-2022-50732

Linux

In the Linux kernel, the following vulnerability has been resolved: staging: rtl8192u: Fix use after free in ieee80211_rx() We cannot dereference the "skb" pointer after calling ieee80211_monitor_rx(), because it is a use after free.

CVSS
8.8
EPSS
0.39%
31.4% percentile
CISA KEV
Not listed
Published
2025.12.24
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.39%
Technical severityCVSS 8.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: staging: rtl8192u: Fix use after free in ieee80211_rx() We cannot dereference the "skb" pointer after calling ieee80211_monitor_rx(), because it is a use after free.

Affected product and versions

Product
Linux
Affected versions
>= 8fc8598e61f6f384f3eaf1d9b09500c12af47b37 < 9c03db0ec84b7964a11b20706665c99a5fead332, >= 8fc8598e61f6f384f3eaf1d9b09500c12af47b37 < fdc62d31d50e4ce5d8f363fcb8299ba0e00ee6fd, >= 8fc8598e61f6f384f3eaf1d9b09500c12af47b37 < a0df8d44b555ae09729d6533fd4532977563c7b9, >= 8fc8598e61f6f384f3eaf1d9b09500c12af47b37 < 288ada16a93aab5aa2ebea8190aafdb35b716854, >= 8fc8598e61f6f384f3eaf1d9b09500c12af47b37 < daa8045a991363ccdae5615d170f35aa1135e7a7, >= 8fc8598e61f6f384f3eaf1d9b09500c12af47b37 < b0aaec894a909c88117c8bda6c7c9b26cf7c744b, >= 8fc8598e61f6f384f3eaf1d9b09500c12af47b37 < de174163c0d319ff06d622e79130a0017c8f5a6e, >= 8fc8598e61f6f384f3eaf1d9b09500c12af47b37 < 73df1172bbcc8d45cd28e3b1a9ca2edb2f9f7ce6, >= 8fc8598e61f6f384f3eaf1d9b09500c12af47b37 < bcc5e2dcf09089b337b76fc1a589f6ff95ca19ac, >= 2.6.33
Fixed versions
No verified fixed-version field is available yet

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE
Not available
CVE-2022-50732 — Linux | SECUFOCUS NOW