cbcvebase.
CVE-2022-50374
published 2025-09-17

CVE-2022-50374: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_{ldisc,serdev}: check percpu_init_rwsem() failure syzbot is reporting NULL…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.19%
8.9th percentile
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_{ldisc,serdev}: check percpu_init_rwsem() failure syzbot is reporting NULL pointer dereference at hci_uart_tty_close() [1], for rcu_sync_enter() is called without rcu_sync_init() due to hci_uart_tty_open() ignoring percpu_init_rwsem() failure. While we are at it, fix that hci_uart_register_device() ignores percpu_init_rwsem() failure and hci_uart_unregister_device() does not call percpu_free_rwsem().

Affected

19 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.0.3-1 (bookworm)linux 6.0.3-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 4.14.63 < 4.154.15
linuxlinux>= 67d2f8781b9f00d1089aafcfa3dc09fcd0f343e2 < d7cc0d51ffcbfd1caaa809fcf9cff05c46d0fb4dd7cc0d51ffcbfd1caaa809fcf9cff05c46d0fb4d
linuxlinux>= 67d2f8781b9f00d1089aafcfa3dc09fcd0f343e2 < b8917dce2134739b39bc0a5648b18427f2cad569b8917dce2134739b39bc0a5648b18427f2cad569
linuxlinux>= 67d2f8781b9f00d1089aafcfa3dc09fcd0f343e2 < 75b2c71ea581c7bb1303860d89366a42ad0506d275b2c71ea581c7bb1303860d89366a42ad0506d2
linuxlinux>= 67d2f8781b9f00d1089aafcfa3dc09fcd0f343e2 < 98ce10f3f345e61fc6c83bff9cd11cda252b05ac98ce10f3f345e61fc6c83bff9cd11cda252b05ac
linuxlinux>= 67d2f8781b9f00d1089aafcfa3dc09fcd0f343e2 < 3124d320c22f3f4388d9ac5c8f37eaad0cefd6b13124d320c22f3f4388d9ac5c8f37eaad0cefd6b1
linuxlinux_kernel>= 0 < 5.10.158-15.10.158-1
linuxlinux_kernel>= 0 < 6.0.3-16.0.3-1
linuxlinux_kernel>= 0 < 6.0.3-16.0.3-1
linuxlinux_kernel>= 0 < 6.0.3-16.0.3-1
linuxlinux_kernel>= 4.14.63 < 4.154.15
linuxlinux_kernel>= 4.14.63 < 5.10.1505.10.150
linuxlinux_kernel>= 5.11 < 5.15.755.15.75
linuxlinux_kernel>= 5.16 < 5.19.175.19.17
linuxlinux_kernel>= 6.0 < 6.0.36.0.3

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.