CVE-2022-50365Buffer Access with Incorrect Length Value in Linux

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 96.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 17

Description

In the Linux kernel, the following vulnerability has been resolved: skbuff: Account for tail adjustment during pull operations Extending the tail can have some unexpected side effects if a program uses a helper like BPF_FUNC_skb_pull_data to read partial content beyond the head skb headlen when all the skbs in the gso frag_list are linear with no head_frag - kernel BUG at net/core/skbuff.c:4219! pc : skb_segment+0xcf4/0xd2c lr : skb_segment+0x63c/0xd2c Call trace: skb_segment+0xcf4/0xd2c __ud

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages4 packages

NVDlinux/linux_kernel4.9.1944.9.337+9
Debianlinux/linux_kernel< 5.10.178-1+3
CVEListV5linux/linux162a5a8c3aff15c449e6b38355cdf80ab4f77a5aff3743d00f41d803e6ab9334962b674f3b7fd0cb+10
debiandebian/linux< linux 6.1.4-1 (bookworm)

Patches

🔴Vulnerability Details

2
GHSA
GHSA-56h4-267j-35wc: In the Linux kernel, the following vulnerability has been resolved: skbuff: Account for tail adjustment during pull operations Extending the tail ca2025-09-17
OSV
CVE-2022-50365: In the Linux kernel, the following vulnerability has been resolved: skbuff: Account for tail adjustment during pull operations Extending the tail can2025-09-17

📋Vendor Advisories

2
Red Hat
kernel: Linux kernel: Local denial of service in skbuff due to improper network buffer handling2025-09-17
Debian
CVE-2022-50365: linux - In the Linux kernel, the following vulnerability has been resolved: skbuff: Acc...2022

💬Community

1
Bugzilla
CVE-2022-50365 kernel: Linux kernel: Local denial of service in skbuff due to improper network buffer handling2025-09-17
CVE-2022-50365 — Linux vulnerability | cvebase