Answer in brief
CVE-2022-49309 records a Unknown severity vulnerability in drivers: staging: rtl8723bs: Fix deadlock in rtw_surveydone_event_callback(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=fb127a61c9d8dfd9b370ee173344d01711f3c698 <c84e5c819600ee0628f61b33d145258ae0f3d7a7 || >=fb127a61c9d8dfd9b370ee173344d01711f3c698 <f89f6c3ebf69623b8ea48200bd690e9e210335a1 || >=fb127a61c9d8dfd9b370ee173344d01711f3c698 <ce129d3efd181da5fd56f4360cc8827122afa67e || >=fb127a61c9d8dfd9b370ee173344d01711f3c698 <2c41f5c341853f84b7bc2f32605d4e2782e8c279 || >=fb127a61c9d8dfd9b370ee173344d01711f3c698 <cc7ad0d77b51c872d629bcd98aea463a3c4109e7 | c84e5c819600ee0628f61b33d145258ae0f3d7a7, f89f6c3ebf69623b8ea48200bd690e9e210335a1, ce129d3efd181da5fd56f4360cc8827122afa67e, 2c41f5c341853f84b7bc2f32605d4e2782e8c279, cc7ad0d77b51c872d629bcd98aea463a3c4109e7 |
| Linux/Linuxgeneric | 5.10 | Not reported |
Published upstream
Feb 26, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 12, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 13, 2026
In the Linux kernel, the following vulnerability has been resolved: drivers: staging: rtl8723bs: Fix deadlock in rtw_surveydone_event_callback() There is a deadlock in rtw_surveydone_event_callback(), which is shown below: (Thread 1) | (Thread 2) | _set_timer() rtw_surveydone_event_callback()| mod_timer() spin_lock_bh() //(1) | (wait a time) ... | rtw_scan_timeout_handler() del_timer_sync() | spin_lock_bh() //(2) (wait timer to stop) | ... We hold pmlmepriv->lock in position (1) of thread 1 and use del_timer_sync() to wait timer to stop, but timer handler also need pmlmepriv->lock in position (2) of thread 2. As a result, rtw_surveydone_event_callback() will block forever. This patch extracts del_timer_sync() from the protection of spin_lock_bh(), which could let timer handler to obtain the needed lock. What`s more, we change spin_lock_bh() in rtw_scan_timeout_handler() to spin_lock_irq(). Otherwise, spin_lock_bh() will also cause deadlock() in timer handler.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2022-49309 records a Unknown severity vulnerability in drivers: staging: rtl8723bs: Fix deadlock in rtw_surveydone_event_callback(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=fb127a61c9d8dfd9b370ee173344d01711f3c698 <c84e5c819600ee0628f61b33d145258ae0f3d7a7 || >=fb127a61c9d8dfd9b370ee173344d01711f3c698 <f89f6c3ebf69623b8ea48200bd690e9e210335a1 || >=fb127a61c9d8dfd9b370ee173344d01711f3c698 <ce129d3efd181da5fd56f4360cc8827122afa67e || >=fb127a61c9d8dfd9b370ee173344d01711f3c698 <2c41f5c341853f84b7bc2f32605d4e2782e8c279 || >=fb127a61c9d8dfd9b370ee173344d01711f3c698 <cc7ad0d77b51c872d629bcd98aea463a3c4109e7 | c84e5c819600ee0628f61b33d145258ae0f3d7a7, f89f6c3ebf69623b8ea48200bd690e9e210335a1, ce129d3efd181da5fd56f4360cc8827122afa67e, 2c41f5c341853f84b7bc2f32605d4e2782e8c279, cc7ad0d77b51c872d629bcd98aea463a3c4109e7 |
| Linux/Linuxgeneric | 5.10 | Not reported |
Published upstream
Feb 26, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 12, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 13, 2026
In the Linux kernel, the following vulnerability has been resolved: drivers: staging: rtl8723bs: Fix deadlock in rtw_surveydone_event_callback() There is a deadlock in rtw_surveydone_event_callback(), which is shown below: (Thread 1) | (Thread 2) | _set_timer() rtw_surveydone_event_callback()| mod_timer() spin_lock_bh() //(1) | (wait a time) ... | rtw_scan_timeout_handler() del_timer_sync() | spin_lock_bh() //(2) (wait timer to stop) | ... We hold pmlmepriv->lock in position (1) of thread 1 and use del_timer_sync() to wait timer to stop, but timer handler also need pmlmepriv->lock in position (2) of thread 2. As a result, rtw_surveydone_event_callback() will block forever. This patch extracts del_timer_sync() from the protection of spin_lock_bh(), which could let timer handler to obtain the needed lock. What`s more, we change spin_lock_bh() in rtw_scan_timeout_handler() to spin_lock_irq(). Otherwise, spin_lock_bh() will also cause deadlock() in timer handler.
Quoted source text, attributed separately from HOL analysis.