cbcvebase.
CVE-2022-50368
published 2025-09-17

CVE-2022-50368: In the Linux kernel, the following vulnerability has been resolved: drm/msm/dsi: fix memory corruption with too many bridges Add the missing sanity check on…

PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.20%
10.1th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/msm/dsi: fix memory corruption with too many bridges Add the missing sanity check on the bridge counter to avoid corrupting data beyond the fixed-sized bridge array in case there are ever more than eight bridges. Patchwork: https://patchwork.freedesktop.org/patch/502668/

Affected

18 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.0.7-1 (bookworm)linux 6.0.7-1 (bookworm)
linuxlinux
linuxlinux>= a689554ba6ed81cf606c16539f6ffc2a1dcdaf8e < 4e5587cddb334f7a5bb1c49ea8bbfc966fafe1b84e5587cddb334f7a5bb1c49ea8bbfc966fafe1b8
linuxlinux>= a689554ba6ed81cf606c16539f6ffc2a1dcdaf8e < f649ed0e1b7a1545f8e27267d3c468b3cb222ecef649ed0e1b7a1545f8e27267d3c468b3cb222ece
linuxlinux>= a689554ba6ed81cf606c16539f6ffc2a1dcdaf8e < 21c4679af01f1027cb559330c2e7d410089b2b3621c4679af01f1027cb559330c2e7d410089b2b36
linuxlinux>= a689554ba6ed81cf606c16539f6ffc2a1dcdaf8e < 9f035d1fb30648fe70ee01627eb131c56d699b359f035d1fb30648fe70ee01627eb131c56d699b35
linuxlinux>= a689554ba6ed81cf606c16539f6ffc2a1dcdaf8e < e83b354890a3c1d5256162f87a6cc38c47ae7f20e83b354890a3c1d5256162f87a6cc38c47ae7f20
linuxlinux>= a689554ba6ed81cf606c16539f6ffc2a1dcdaf8e < 2e786eb2f9cebb07e317226b60054df510b60c652e786eb2f9cebb07e317226b60054df510b60c65
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.158-15.10.158-1
linuxlinux_kernel>= 0 < 6.0.7-16.0.7-1
linuxlinux_kernel>= 0 < 6.0.7-16.0.7-1
linuxlinux_kernel>= 0 < 6.0.7-16.0.7-1
linuxlinux_kernel>= 4.1 < 4.19.2644.19.264
linuxlinux_kernel>= 4.20 < 5.4.2235.4.223
linuxlinux_kernel>= 5.11 < 5.15.775.15.77
linuxlinux_kernel>= 5.16 < 6.0.76.0.7
linuxlinux_kernel>= 5.5 < 5.10.1535.10.153

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.