CVE-2022-50266
published 2025-09-15CVE-2022-50266: In the Linux kernel, the following vulnerability has been resolved: kprobes: Fix check for probe enabled in kill_kprobe() In kill_kprobe(), the check whether…
PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.14%
4.1th percentile
In the Linux kernel, the following vulnerability has been resolved:
kprobes: Fix check for probe enabled in kill_kprobe()
In kill_kprobe(), the check whether disarm_kprobe_ftrace() needs to be
called always fails. This is because before that we set the
KPROBE_FLAG_GONE flag for kprobe so that "!kprobe_disabled(p)" is always
false.
The disarm_kprobe_ftrace() call introduced by commit:
0cb2f1372baa ("kprobes: Fix NULL pointer dereference at kprobe_ftrace_handler")
to fix the NULL pointer reference problem. When the probe is enabled, if
we do not disarm it, this problem still exists.
Fix it by putting the probe enabled check before setting the
KPROBE_FLAG_GONE flag.
Affected
32 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.4-1 (bookworm) | linux 6.1.4-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | >= 3031313eb3d549b7ad6f9fbcc52ba04412e3eb9e < f20a067f13106565816b4b6a6b665b2088a63824 | f20a067f13106565816b4b6a6b665b2088a63824 |
| linux | linux | >= 3031313eb3d549b7ad6f9fbcc52ba04412e3eb9e < c909985dd0c0f74b61e3f8f0e04bf8aa9c8b97c7 | c909985dd0c0f74b61e3f8f0e04bf8aa9c8b97c7 |
| linux | linux | >= 3031313eb3d549b7ad6f9fbcc52ba04412e3eb9e < 0c76ef3f26d5ef2ac2c21b47e7620cff35809fbb | 0c76ef3f26d5ef2ac2c21b47e7620cff35809fbb |
| linux | linux | >= 4.14.200 < 4.15 | 4.15 |
| linux | linux | >= 4.19.149 < 4.20 | 4.20 |
| linux | linux | >= 4.4.238 < 4.5 | 4.5 |
| linux | linux | >= 4.9.238 < 4.10 | 4.10 |
| linux | linux | >= 5.4.69 < 5.5 | 5.5 |
| linux | linux | >= 5.8.13 < 5.9 | 5.9 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 4.14.200 < 4.15 | 4.15 |
| linux | linux_kernel | >= 4.19.149 < 4.20 | 4.20 |
| linux | linux_kernel | >= 4.4.238 < 4.5 | 4.5 |
| linux | linux_kernel | >= 4.9.238 < 4.10 | 4.10 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: kprobes: Fix check for probe enabled in kill_kprobe()
vendor_redhat·2025-09-15·CVSS 5.5
CVE-2022-50266 [MEDIUM] CWE-570 kernel: kprobes: Fix check for probe enabled in kill_kprobe()
kernel: kprobes: Fix check for probe enabled in kill_kprobe()
In the Linux kernel, the following vulnerability has been resolved:
kprobes: Fix check for probe enabled in kill_kprobe()
In kill_kprobe(), the check whether disarm_kprobe_ftrace() needs to be
called always fails. This is because before that we set the
KPROBE_FLAG_GONE flag for kprobe so that "!kprobe_disabled(p)" is always
false.
The disarm_kprobe_ftrace() call introduced by commit:
0cb2f1372baa ("kprobes: Fix NULL pointer dereference at kprobe_ftrace_handler")
to fix the NULL pointer reference problem. When the probe is enabled, if
we do not disarm it, this problem still exists.
Fix it by putting the probe enabled check before setting the
KPROBE_FLAG_GONE flag.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Pa
Microsoft
kprobes: Fix check for probe enabled in kill_kprobe()
vendor_msrc·2025-09-09·CVSS 5.5
CVE-2022-50266 [MEDIUM] CWE-476 kprobes: Fix check for probe enabled in kill_kprobe()
kprobes: Fix check for probe enabled in kill_kprobe()
Mariner: Mariner
Linux: Linux
Customer Action Required: Yes
Debian
CVE-2022-50266: linux - In the Linux kernel, the following vulnerability has been resolved: kprobes: Fi...
vendor_debian·2022·CVSS 5.5
CVE-2022-50266 [MEDIUM] CVE-2022-50266: linux - In the Linux kernel, the following vulnerability has been resolved: kprobes: Fi...
In the Linux kernel, the following vulnerability has been resolved: kprobes: Fix check for probe enabled in kill_kprobe() In kill_kprobe(), the check whether disarm_kprobe_ftrace() needs to be called always fails. This is because before that we set the KPROBE_FLAG_GONE flag for kprobe so that "!kprobe_disabled(p)" is always false. The disarm_kprobe_ftrace() call introduced by commit: 0cb2f1372baa ("kprobes: Fix NULL pointer dereference at kprobe_ftrace_handler") to fix the NULL pointer reference problem. When the probe is enabled, if we do not disarm it, this problem still exists. Fix it by putting the probe enabled check before setting the KPROBE_FLAG_GONE flag.
Scope: local
bookworm: resolved (fixed in 6.1.4-1)
bullseye: open
forky: resolved (fixed in 6.1.4-1)
sid: resolved (fixed in 6.1
OSV
CVE-2022-50266: In the Linux kernel, the following vulnerability has been resolved: kprobes: Fix check for probe enabled in kill_kprobe() In kill_kprobe(), the check
osv·2025-09-15·CVSS 5.5
CVE-2022-50266 [MEDIUM] CVE-2022-50266: In the Linux kernel, the following vulnerability has been resolved: kprobes: Fix check for probe enabled in kill_kprobe() In kill_kprobe(), the check
In the Linux kernel, the following vulnerability has been resolved: kprobes: Fix check for probe enabled in kill_kprobe() In kill_kprobe(), the check whether disarm_kprobe_ftrace() needs to be called always fails. This is because before that we set the KPROBE_FLAG_GONE flag for kprobe so that "!kprobe_disabled(p)" is always false. The disarm_kprobe_ftrace() call introduced by commit: 0cb2f1372baa ("kprobes: Fix NULL pointer dereference at kprobe_ftrace_handler") to fix the NULL pointer reference problem. When the probe is enabled, if we do not disarm it, this problem still exists. Fix it by putting the probe enabled check before setting the KPROBE_FLAG_GONE flag.
GHSA
GHSA-gcqm-mw5p-q5gh: In the Linux kernel, the following vulnerability has been resolved:
kprobes: Fix check for probe enabled in kill_kprobe()
In kill_kprobe(), the chec
ghsa_unreviewed·2025-09-15
CVE-2022-50266 [MEDIUM] CWE-476 GHSA-gcqm-mw5p-q5gh: In the Linux kernel, the following vulnerability has been resolved:
kprobes: Fix check for probe enabled in kill_kprobe()
In kill_kprobe(), the chec
In the Linux kernel, the following vulnerability has been resolved:
kprobes: Fix check for probe enabled in kill_kprobe()
In kill_kprobe(), the check whether disarm_kprobe_ftrace() needs to be
called always fails. This is because before that we set the
KPROBE_FLAG_GONE flag for kprobe so that "!kprobe_disabled(p)" is always
false.
The disarm_kprobe_ftrace() call introduced by commit:
0cb2f1372baa ("kprobes: Fix NULL pointer dereference at kprobe_ftrace_handler")
to fix the NULL pointer reference problem. When the probe is enabled, if
we do not disarm it, this problem still exists.
Fix it by putting the probe enabled check before setting the
KPROBE_FLAG_GONE flag.
No detection rules found.
No public exploits indexed.
2025-09-15
Published