cbcvebase.
CVE-2022-50080
published 2025-06-18

CVE-2022-50080: In the Linux kernel, the following vulnerability has been resolved: tee: add overflow check in register_shm_helper() With special lengths supplied by user…

PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.22%
12.9th percentile
In the Linux kernel, the following vulnerability has been resolved: tee: add overflow check in register_shm_helper() With special lengths supplied by user space, register_shm_helper() has an integer overflow when calculating the number of pages covered by a supplied user space memory region. This causes internal_get_user_pages_fast() a helper function of pin_user_pages_fast() to do a NULL pointer dereference: Unable to handle kernel NULL pointer dereference at virtual address 0000000000000010 Modules linked in: CPU: 1 PID: 173 Comm: optee_example_a Not tainted 5.19.0 #11 Hardware name: QEMU QEMU Virtual Machine, BIOS 0.0.0 02/06/2015 pc : internal_get_user_pages_fast+0x474/0xa80 Call trace: internal_get_user_pages_fast+0x474/0xa80 pin_user_pages_fast+0x24/0x4c register_shm_helper+0x194/0x330 tee_shm_register_user_buf+0x78/0x120 tee_ioctl+0xd0/0x11a0 __arm64_sys_ioctl+0xa8/0xec invoke_syscall+0x48/0x114 Fix this by adding an an explicit call to access_ok() in tee_shm_register_user_buf() to catch an invalid user space address early.

Affected

20 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.0.2-1 (bookworm)linux 6.0.2-1 (bookworm)
linuxlinux
linuxlinux>= 033ddf12bcf5326b93bd604f50a7474a434a35f9 < b37e0f17653c00b586cdbcdf0dbca475358ecffdb37e0f17653c00b586cdbcdf0dbca475358ecffd
linuxlinux>= 033ddf12bcf5326b93bd604f50a7474a434a35f9 < 965333345fe952cc7eebc8e3a565ffc709441af2965333345fe952cc7eebc8e3a565ffc709441af2
linuxlinux>= 033ddf12bcf5326b93bd604f50a7474a434a35f9 < 578c349570d2a912401963783b36e0ec7a25c053578c349570d2a912401963783b36e0ec7a25c053
linuxlinux>= 033ddf12bcf5326b93bd604f50a7474a434a35f9 < c12f0e6126ad223806a365084e86370511654bf1c12f0e6126ad223806a365084e86370511654bf1
linuxlinux>= 033ddf12bcf5326b93bd604f50a7474a434a35f9 < 2f8e79a1a6128214cb9b205a9869341af5dfb16b2f8e79a1a6128214cb9b205a9869341af5dfb16b
linuxlinux>= 033ddf12bcf5326b93bd604f50a7474a434a35f9 < 58c008d4d398f792ca67f35650610864725518fd58c008d4d398f792ca67f35650610864725518fd
linuxlinux>= 033ddf12bcf5326b93bd604f50a7474a434a35f9 < 573ae4f13f630d6660008f1974c0a8a29c30e18a573ae4f13f630d6660008f1974c0a8a29c30e18a
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.140-15.10.140-1
linuxlinux_kernel>= 0 < 6.0.2-16.0.2-1
linuxlinux_kernel>= 0 < 6.0.2-16.0.2-1
linuxlinux_kernel>= 0 < 6.0.2-16.0.2-1
linuxlinux_kernel>= 4.16 < 4.19.2564.19.256
linuxlinux_kernel>= 4.20 < 5.4.2115.4.211
linuxlinux_kernel>= 5.11 < 5.15.625.15.62
linuxlinux_kernel>= 5.16 < 5.18.195.18.19
linuxlinux_kernel>= 5.19 < 5.19.35.19.3
linuxlinux_kernel>= 5.5 < 5.10.1375.10.137

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.