{"id":"DEBIAN-CVE-2022-50187","details":"In the Linux kernel, the following vulnerability has been resolved:  ath11k: fix netdev open race  Make sure to allocate resources needed before registering the device.  This specifically avoids having a racing open() trigger a BUG_ON() in mod_timer() when ath11k_mac_op_start() is called before the mon_reap_timer as been set up.  I did not see this issue with next-20220310, but I hit it on every probe with next-20220511. Perhaps some timing changed in between.  Here's the backtrace:  [   51.346947] kernel BUG at kernel/time/timer.c:990! [   51.346958] Internal error: Oops - BUG: 0 [#1] PREEMPT SMP ... [   51.578225] Call trace: [   51.583293]  __mod_timer+0x298/0x390 [   51.589518]  mod_timer+0x14/0x20 [   51.595368]  ath11k_mac_op_start+0x41c/0x4a0 [ath11k] [   51.603165]  drv_start+0x38/0x60 [mac80211] [   51.610110]  ieee80211_do_open+0x29c/0x7d0 [mac80211] [   51.617945]  ieee80211_open+0x60/0xb0 [mac80211] [   51.625311]  __dev_open+0x100/0x1c0 [   51.631420]  __dev_change_flags+0x194/0x210 [   51.638214]  dev_change_flags+0x24/0x70 [   51.644646]  do_setlink+0x228/0xdb0 [   51.650723]  __rtnl_newlink+0x460/0x830 [   51.657162]  rtnl_newlink+0x4c/0x80 [   51.663229]  rtnetlink_rcv_msg+0x124/0x390 [   51.669917]  netlink_rcv_skb+0x58/0x130 [   51.676314]  rtnetlink_rcv+0x18/0x30 [   51.682460]  netlink_unicast+0x250/0x310 [   51.688960]  netlink_sendmsg+0x19c/0x3e0 [   51.695458]  ____sys_sendmsg+0x220/0x290 [   51.701938]  ___sys_sendmsg+0x7c/0xc0 [   51.708148]  __sys_sendmsg+0x68/0xd0 [   51.714254]  __arm64_sys_sendmsg+0x28/0x40 [   51.720900]  invoke_syscall+0x48/0x120  Tested-on: WCN6855 hw2.0 PCI WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3","modified":"2026-09-01T16:05:34.874209289Z","published":"2025-06-18T11:15:49.267Z","upstream":["CVE-2022-50187"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2022-50187"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.0.2-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-50187.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.0.2-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-50187.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.0.2-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-50187.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}