cbcvebase.
CVE-2022-50028
published 2025-06-18

CVE-2022-50028: In the Linux kernel, the following vulnerability has been resolved: gadgetfs: ep_io - wait until IRQ finishes after usb_ep_queue() if…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.17%
6.5th percentile
In the Linux kernel, the following vulnerability has been resolved: gadgetfs: ep_io - wait until IRQ finishes after usb_ep_queue() if wait_for_completion_interruptible() is interrupted we need to wait until IRQ gets finished. Otherwise complete() from epio_complete() can corrupt stack.

Affected

21 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.0.2-1 (bookworm)linux 6.0.2-1 (bookworm)
linuxlinux
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 67a4874461422e633236a0286a01b483cd64711367a4874461422e633236a0286a01b483cd647113
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 118d967ce00a3d128bf731b35e4e2cb0facf5f00118d967ce00a3d128bf731b35e4e2cb0facf5f00
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 77040efe59a141286d090c8a0d37c65a355a183277040efe59a141286d090c8a0d37c65a355a1832
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < ca06b4cde54f8ec8be3aa53fd339bd56e62c12b3ca06b4cde54f8ec8be3aa53fd339bd56e62c12b3
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 9ac14f973cb91f0c01776517e6d50981f32b80389ac14f973cb91f0c01776517e6d50981f32b8038
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 94aadba8d000d5de56af4ce8da3f334f21bf7a7994aadba8d000d5de56af4ce8da3f334f21bf7a79
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 2b06d5d97c0e067108a122986767731d407421382b06d5d97c0e067108a122986767731d40742138
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 04cb742d4d8f30dc2e83b46ac317eec09191c68e04cb742d4d8f30dc2e83b46ac317eec09191c68e
linuxlinux_kernel< 4.9.3264.9.326
linuxlinux_kernel>= 0 < 5.10.140-15.10.140-1
linuxlinux_kernel>= 0 < 6.0.2-16.0.2-1
linuxlinux_kernel>= 0 < 6.0.2-16.0.2-1
linuxlinux_kernel>= 0 < 6.0.2-16.0.2-1
linuxlinux_kernel>= 4.10 < 4.14.2914.14.291
linuxlinux_kernel>= 4.15 < 4.19.2564.19.256
linuxlinux_kernel>= 4.20 < 5.4.2115.4.211
linuxlinux_kernel>= 5.11 < 5.15.635.15.63
linuxlinux_kernel>= 5.16 < 5.19.45.19.4
linuxlinux_kernel>= 5.5 < 5.10.1385.10.138

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.