CVE-2022-50094
published 2025-06-18CVE-2022-50094: In the Linux kernel, the following vulnerability has been resolved: spmi: trace: fix stack-out-of-bound access in SPMI tracing functions…
PriorityP431high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.22%
12.3th percentile
In the Linux kernel, the following vulnerability has been resolved:
spmi: trace: fix stack-out-of-bound access in SPMI tracing functions
trace_spmi_write_begin() and trace_spmi_read_end() both call
memcpy() with a length of "len + 1". This leads to one extra
byte being read beyond the end of the specified buffer. Fix
this out-of-bound memory access by using a length of "len"
instead.
Here is a KASAN log showing the issue:
BUG: KASAN: stack-out-of-bounds in trace_event_raw_event_spmi_read_end+0x1d0/0x234
Read of size 2 at addr ffffffc0265b7540 by task [email protected]/1314
...
Call trace:
dump_backtrace+0x0/0x3e8
show_stack+0x2c/0x3c
dump_stack_lvl+0xdc/0x11c
print_address_description+0x74/0x384
kasan_report+0x188/0x268
kasan_check_range+0x270/0x2b0
memcpy+0x90/0xe8
trace_event_raw_event_spmi_read_end+0x1d0/0x234
spmi_read_cmd+0x294/0x3ac
spmi_ext_register_readl+0x84/0x9c
regmap_spmi_ext_read+0x144/0x1b0 [regmap_spmi]
_regmap_raw_read+0x40c/0x754
regmap_raw_read+0x3a0/0x514
regmap_bulk_read+0x418/0x494
adc5_gen3_poll_wait_hs+0xe8/0x1e0 [qcom_spmi_adc5_gen3]
...
__arm64_sys_read+0x4c/0x60
invoke_syscall+0x80/0x218
el0_svc_common+0xec/0x1c8
...
addr ffffffc0265b7540 is located in stack of task [email protected]/1314 at offset 32 in frame:
adc5_gen3_poll_wait_hs+0x0/0x1e0 [qcom_spmi_adc5_gen3]
this frame has 1 object:
[32, 33) 'status'
Memory state around the buggy address:
ffffffc0265b7400: 00 00 00 00 00 00 00 00 00 00 00 00 f1 f1 f1 f1
ffffffc0265b7480: 04 f3 f3 f3 00 00 00 00 00 00 00 00 00 00 00 00
>ffffffc0265b7500: 00 00 00 00 f1 f1 f1 f1 01 f3 f3 f3 00 00 00 00
^
ffffffc0265b7580: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
ffffffc0265b7600: f1 f1 f1 f1 01 f2 07 f2 f2 f2 01 f3 00 00 00 00
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.0.2-1 (bookworm) | linux 6.0.2-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= a9fce374815d8ab94a3e6259802a944e2cc21408 < 80f7c93e573ea9f524924bb529c2af8cb28b1c43 | 80f7c93e573ea9f524924bb529c2af8cb28b1c43 |
| linux | linux | >= a9fce374815d8ab94a3e6259802a944e2cc21408 < dc6033a7761254e5a5ba7df36b64db787a53313c | dc6033a7761254e5a5ba7df36b64db787a53313c |
| linux | linux | >= a9fce374815d8ab94a3e6259802a944e2cc21408 < ac730c72bddc889f5610d51d8a7abf425e08da1a | ac730c72bddc889f5610d51d8a7abf425e08da1a |
| linux | linux | >= a9fce374815d8ab94a3e6259802a944e2cc21408 < 37690cb8662cec672cacda19e6e4fd2ca7b13f0b | 37690cb8662cec672cacda19e6e4fd2ca7b13f0b |
| linux | linux | >= a9fce374815d8ab94a3e6259802a944e2cc21408 < dd02510fb43168310abfd0b9ccf49993a722fb91 | dd02510fb43168310abfd0b9ccf49993a722fb91 |
| linux | linux | >= a9fce374815d8ab94a3e6259802a944e2cc21408 < 1e0ca3d809c36ad3d1f542917718fc22ec6316e7 | 1e0ca3d809c36ad3d1f542917718fc22ec6316e7 |
| linux | linux | >= a9fce374815d8ab94a3e6259802a944e2cc21408 < bcc1b6b1ed3f42ed25858c1f1eb24a2f741db93f | bcc1b6b1ed3f42ed25858c1f1eb24a2f741db93f |
| linux | linux | >= a9fce374815d8ab94a3e6259802a944e2cc21408 < 504090815c1ad3fd3fa34618b54d706727f8911c | 504090815c1ad3fd3fa34618b54d706727f8911c |
| linux | linux | >= a9fce374815d8ab94a3e6259802a944e2cc21408 < 2af28b241eea816e6f7668d1954f15894b45d7e3 | 2af28b241eea816e6f7668d1954f15894b45d7e3 |
| linux | linux_kernel | >= 0 < 5.10.140-1 | 5.10.140-1 |
| linux | linux_kernel | >= 0 < 6.0.2-1 | 6.0.2-1 |
| linux | linux_kernel | >= 0 < 6.0.2-1 | 6.0.2-1 |
| linux | linux_kernel | >= 0 < 6.0.2-1 | 6.0.2-1 |
| linux | linux_kernel | >= 4.10 < 4.14.291 | 4.14.291 |
| linux | linux_kernel | >= 4.15 < 4.19.256 | 4.19.256 |
| linux | linux_kernel | >= 4.20 < 5.4.211 | 5.4.211 |
| linux | linux_kernel | >= 4.3 < 4.9.326 | 4.9.326 |
| linux | linux_kernel | >= 5.11 < 5.15.61 | 5.15.61 |
| linux | linux_kernel | >= 5.16 < 5.18.18 | 5.18.18 |
| linux | linux_kernel | >= 5.19 < 5.19.2 | 5.19.2 |
| linux | linux_kernel | >= 5.5 < 5.10.137 | 5.10.137 |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-72wp-jhxv-vv38: In the Linux kernel, the following vulnerability has been resolved:
spmi: trace: fix stack-out-of-bound access in SPMI tracing functions
trace_spmi_
ghsa_unreviewed·2025-06-18
CVE-2022-50094 [HIGH] CWE-125 GHSA-72wp-jhxv-vv38: In the Linux kernel, the following vulnerability has been resolved:
spmi: trace: fix stack-out-of-bound access in SPMI tracing functions
trace_spmi_
In the Linux kernel, the following vulnerability has been resolved:
spmi: trace: fix stack-out-of-bound access in SPMI tracing functions
trace_spmi_write_begin() and trace_spmi_read_end() both call
memcpy() with a length of "len + 1". This leads to one extra
byte being read beyond the end of the specified buffer. Fix
this out-of-bound memory access by using a length of "len"
instead.
Here is a KASAN log showing the issue:
BUG: KASAN: stack-out-of-bounds in trace_event_raw_event_spmi_read_end+0x1d0/0x234
Read of size 2 at addr ffffffc0265b7540 by task [email protected]/1314
...
Call trace:
dump_backtrace+0x0/0x3e8
show_stack+0x2c/0x3c
dump_stack_lvl+0xdc/0x11c
print_address_description+0x74/0x384
kasan_report+0x188/0x268
kasan_check_range+0x270/0x2b0
memcpy+0x90/0xe8
trace_event_raw_event
OSV
CVE-2022-50094: In the Linux kernel, the following vulnerability has been resolved: spmi: trace: fix stack-out-of-bound access in SPMI tracing functions trace_spmi_wr
osv·2025-06-18·CVSS 7.1
CVE-2022-50094 [HIGH] CVE-2022-50094: In the Linux kernel, the following vulnerability has been resolved: spmi: trace: fix stack-out-of-bound access in SPMI tracing functions trace_spmi_wr
In the Linux kernel, the following vulnerability has been resolved: spmi: trace: fix stack-out-of-bound access in SPMI tracing functions trace_spmi_write_begin() and trace_spmi_read_end() both call memcpy() with a length of "len + 1". This leads to one extra byte being read beyond the end of the specified buffer. Fix this out-of-bound memory access by using a length of "len" instead. Here is a KASAN log showing the issue: BUG: KASAN: stack-out-of-bounds in trace_event_raw_event_spmi_read_end+0x1d0/0x234 Read of size 2 at addr ffffffc0265b7540 by task [email protected]/1314 ... Call trace: dump_backtrace+0x0/0x3e8 show_stack+0x2c/0x3c dump_stack_lvl+0xdc/0x11c print_address_description+0x74/0x384 kasan_report+0x188/0x268 kasan_check_range+0x270/0x2b0 memcpy+0x90/0xe8 trace_event_raw_event_spm
Red Hat
kernel: spmi: trace: fix stack-out-of-bound access in SPMI tracing functions
vendor_redhat·2025-06-18·CVSS 7.1
CVE-2022-50094 [HIGH] CWE-125 kernel: spmi: trace: fix stack-out-of-bound access in SPMI tracing functions
kernel: spmi: trace: fix stack-out-of-bound access in SPMI tracing functions
In the Linux kernel, the following vulnerability has been resolved:
spmi: trace: fix stack-out-of-bound access in SPMI tracing functions
trace_spmi_write_begin() and trace_spmi_read_end() both call
memcpy() with a length of "len + 1". This leads to one extra
byte being read beyond the end of the specified buffer. Fix
this out-of-bound memory access by using a length of "len"
instead.
Here is a KASAN log showing the issue:
BUG: KASAN: stack-out-of-bounds in trace_event_raw_event_spmi_read_end+0x1d0/0x234
Read of size 2 at addr ffffffc0265b7540 by task [email protected]/1314
...
Call trace:
dump_backtrace+0x0/0x3e8
show_stack+0x2c/0x3c
dump_stack_lvl+0xdc/0x11c
print_address_description+0x74/0x384
kasan_report+0x188/
Debian
CVE-2022-50094: linux - In the Linux kernel, the following vulnerability has been resolved: spmi: trace...
vendor_debian·2022·CVSS 7.1
CVE-2022-50094 [HIGH] CVE-2022-50094: linux - In the Linux kernel, the following vulnerability has been resolved: spmi: trace...
In the Linux kernel, the following vulnerability has been resolved: spmi: trace: fix stack-out-of-bound access in SPMI tracing functions trace_spmi_write_begin() and trace_spmi_read_end() both call memcpy() with a length of "len + 1". This leads to one extra byte being read beyond the end of the specified buffer. Fix this out-of-bound memory access by using a length of "len" instead. Here is a KASAN log showing the issue: BUG: KASAN: stack-out-of-bounds in trace_event_raw_event_spmi_read_end+0x1d0/0x234 Read of size 2 at addr ffffffc0265b7540 by task [email protected]/1314 ... Call trace: dump_backtrace+0x0/0x3e8 show_stack+0x2c/0x3c dump_stack_lvl+0xdc/0x11c print_address_description+0x74/0x384 kasan_report+0x188/0x268 kasan_check_range+0x270/0x2b0 memcpy+0x90/0xe8 trace_event_raw_event_spm
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/1e0ca3d809c36ad3d1f542917718fc22ec6316e7https://git.kernel.org/stable/c/2af28b241eea816e6f7668d1954f15894b45d7e3https://git.kernel.org/stable/c/37690cb8662cec672cacda19e6e4fd2ca7b13f0bhttps://git.kernel.org/stable/c/504090815c1ad3fd3fa34618b54d706727f8911chttps://git.kernel.org/stable/c/80f7c93e573ea9f524924bb529c2af8cb28b1c43https://git.kernel.org/stable/c/ac730c72bddc889f5610d51d8a7abf425e08da1ahttps://git.kernel.org/stable/c/bcc1b6b1ed3f42ed25858c1f1eb24a2f741db93fhttps://git.kernel.org/stable/c/dc6033a7761254e5a5ba7df36b64db787a53313chttps://git.kernel.org/stable/c/dd02510fb43168310abfd0b9ccf49993a722fb91
2025-06-18
Published