A use-after-free flaw in the Linux kernel's ath9k_htc Atheros USB Wi-Fi driver, tracked as CVE-2022-1679, can be triggered by a local low-privileged user using crafted input messages. The bug occurs when driver initialization fails after drv_priv is assigned: hardware-private data may be freed while an asynchronous receive callback still accesses it, causing a kernel crash and potentially exposing memory. The original report also identified a possible privilege-escalation condition.
Red Hat assigned the issue a Moderate severity rating with CVSS 7.0 and released fixes for supported Red Hat Enterprise Linux 8 and 9 kernel variants. Although exploitation for privilege escalation is assessed as unlikely because it depends on difficult race conditions, organizations should deploy updated kernels or prevent the ath9k module from loading where the adapter is not needed. RHEL 6 and 7 kernel packages are outside support scope and should be treated as affected unless mitigated or upgraded.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2023:2951 and RHSA-2023:2736 to fix CVE-2022-1679 in supported RHEL 8 kernel and kernel-rt packages.
Red Hat issued RHSA-2022:8267 and RHSA-2022:7933, providing fixed RHEL 9 kernel and kernel-rt packages for CVE-2022-1679.
Pavel Skripkin submitted a proposed patch moving drv_priv assignment until successful initialization and making driver statistics macros safe when drv_priv is NULL. Reviewers requested macro cleanup and syzbot-report links for a subsequent revision.
RHSA-2024:0412 provided a CVE-2022-1679 kernel fix for RHEL 8.6 Extended Update Support and Red Hat Virtualization 4 for RHEL 8.
syzbot reported a use-after-free read in the Linux ath9k HTC USB Wi-Fi driver, and Elijahbai of Tencent Security Yunding Lab reported the vulnerability to Red Hat. The failure path can leave drv_priv pointing to freed private data after ath9k_htc_wait_for_target() fails.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.