cbcvebase.
CVE-2022-50382
published 2025-09-18

CVE-2022-50382: In the Linux kernel, the following vulnerability has been resolved: padata: Always leave BHs disabled when running ->parallel() A deadlock can happen when an…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.11%
1.5th percentile
In the Linux kernel, the following vulnerability has been resolved: padata: Always leave BHs disabled when running ->parallel() A deadlock can happen when an overloaded system runs ->parallel() in the context of the current task: padata_do_parallel ->parallel() pcrypt_aead_enc/dec padata_do_serial spin_lock(&reorder->lock) // BHs still enabled ... __do_softirq ... padata_do_serial spin_lock(&reorder->lock) It's a bug for BHs to be on in _do_serial as Steffen points out, so ensure they're off in the "current task" case like they are in padata_parallel_worker to avoid this situation.

Affected

15 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.4-1 (bookworm)linux 6.1.4-1 (bookworm)
linuxlinux
linuxlinux>= 4611ce22468895acd61fee9ac1da810d60617d9a < 8e0681dd4eee029eb1d533d06993f7cb091efb738e0681dd4eee029eb1d533d06993f7cb091efb73
linuxlinux>= 4611ce22468895acd61fee9ac1da810d60617d9a < 17afa98bccec4f52203508b3f49b5f948c6fd6ac17afa98bccec4f52203508b3f49b5f948c6fd6ac
linuxlinux>= 4611ce22468895acd61fee9ac1da810d60617d9a < 7337adb20fcc0aebb50eaff2bc5a8dd9a7c6743d7337adb20fcc0aebb50eaff2bc5a8dd9a7c6743d
linuxlinux>= 4611ce22468895acd61fee9ac1da810d60617d9a < 6cfa9e60c0f88fdec6368e081ab968411cc706b16cfa9e60c0f88fdec6368e081ab968411cc706b1
linuxlinux>= 4611ce22468895acd61fee9ac1da810d60617d9a < 34c3a47d20ae55b3600fed733bf96eafe9c500d534c3a47d20ae55b3600fed733bf96eafe9c500d5
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 5.11 < 5.15.865.15.86
linuxlinux_kernel>= 5.16 < 6.0.166.0.16
linuxlinux_kernel>= 5.8 < 5.10.1635.10.163
linuxlinux_kernel>= 6.1 < 6.1.26.1.2

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.