cbcvebase.
CVE-2022-50036
published 2025-06-18

CVE-2022-50036: In the Linux kernel, the following vulnerability has been resolved: drm/sun4i: dsi: Prevent underflow when computing packet sizes Currently, the packet…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.16%
5.5th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/sun4i: dsi: Prevent underflow when computing packet sizes Currently, the packet overhead is subtracted using unsigned arithmetic. With a short sync pulse, this could underflow and wrap around to near the maximal u16 value. Fix this by using signed subtraction. The call to max() will correctly handle any negative numbers that are produced. Apply the same fix to the other timings, even though those subtractions are less likely to underflow.

Affected

14 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.0.2-1 (bookworm)linux 6.0.2-1 (bookworm)
linuxlinux
linuxlinux>= 133add5b5ad42b7bb5fcd59d681aef6475d08600 < a1e7908f78f5a7f53f8cd83c7dcdfec974c95f26a1e7908f78f5a7f53f8cd83c7dcdfec974c95f26
linuxlinux>= 133add5b5ad42b7bb5fcd59d681aef6475d08600 < 98e28de472ef248352f04f87e29e634ebb0ec24098e28de472ef248352f04f87e29e634ebb0ec240
linuxlinux>= 133add5b5ad42b7bb5fcd59d681aef6475d08600 < fb837f5b83461624e525727a8f4add14b201147efb837f5b83461624e525727a8f4add14b201147e
linuxlinux>= 133add5b5ad42b7bb5fcd59d681aef6475d08600 < 82a1356a933d8443139f8886f11b63c974a09a6782a1356a933d8443139f8886f11b63c974a09a67
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.140-15.10.140-1
linuxlinux_kernel>= 0 < 6.0.2-16.0.2-1
linuxlinux_kernel>= 0 < 6.0.2-16.0.2-1
linuxlinux_kernel>= 0 < 6.0.2-16.0.2-1
linuxlinux_kernel>= 4.18 < 5.10.1385.10.138
linuxlinux_kernel>= 5.11 < 5.15.635.15.63
linuxlinux_kernel>= 5.16 < 5.19.45.19.4

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.