CVE-2022-50407
published 2025-09-18CVE-2022-50407: In the Linux kernel, the following vulnerability has been resolved: crypto: hisilicon/qm - increase the memory of local variables Increase the buffer to…
PriorityP424medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.16%
5.6th percentile
In the Linux kernel, the following vulnerability has been resolved:
crypto: hisilicon/qm - increase the memory of local variables
Increase the buffer to prevent stack overflow by fuzz test. The maximum
length of the qos configuration buffer is 256 bytes. Currently, the value
of the 'val buffer' is only 32 bytes. The sscanf does not check the dest
memory length. So the 'val buffer' may stack overflow.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.4-1 (bookworm) | linux 6.1.4-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 263c9959c9376ec0217d6adc61222a53469eed3c < 34c4f8ad45b4ea814c7ecc3f23a2d292959d5a52 | 34c4f8ad45b4ea814c7ecc3f23a2d292959d5a52 |
| linux | linux | >= 263c9959c9376ec0217d6adc61222a53469eed3c < fc521abb6ee4b8f06fdfc52646140dab6a2ed334 | fc521abb6ee4b8f06fdfc52646140dab6a2ed334 |
| linux | linux | >= 263c9959c9376ec0217d6adc61222a53469eed3c < 3efe90af4c0c46c58dba1b306de142827153d9c0 | 3efe90af4c0c46c58dba1b306de142827153d9c0 |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 5.4 < 6.0.16 | 6.0.16 |
| linux | linux_kernel | >= 6.1 < 6.1.2 | 6.1.2 |
| msrc | cbl2_kernel_5.15.186.1-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_kernel_5.15.200.1-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_kernel_5.15.202.1-1_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: crypto: hisilicon/qm - increase the memory of local variables
vendor_redhat·2025-09-18·CVSS 5.5
CVE-2022-50407 [MEDIUM] kernel: crypto: hisilicon/qm - increase the memory of local variables
kernel: crypto: hisilicon/qm - increase the memory of local variables
In the Linux kernel, the following vulnerability has been resolved:
crypto: hisilicon/qm - increase the memory of local variables
Increase the buffer to prevent stack overflow by fuzz test. The maximum
length of the qos configuration buffer is 256 bytes. Currently, the value
of the 'val buffer' is only 32 bytes. The sscanf does not check the dest
memory length. So the 'val buffer' may stack overflow.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Package: kernel
Microsoft
crypto: hisilicon/qm - increase the memory of local variables
vendor_msrc·2025-09-09·CVSS 5.5
CVE-2022-50407 [MEDIUM] CWE-674 crypto: hisilicon/qm - increase the memory of local variables
crypto: hisilicon/qm - increase the memory of local variables
Mariner: Mariner
Linux: Linux
Customer Action Required: Yes
Debian
CVE-2022-50407: linux - In the Linux kernel, the following vulnerability has been resolved: crypto: his...
vendor_debian·2022·CVSS 5.5
CVE-2022-50407 [MEDIUM] CVE-2022-50407: linux - In the Linux kernel, the following vulnerability has been resolved: crypto: his...
In the Linux kernel, the following vulnerability has been resolved: crypto: hisilicon/qm - increase the memory of local variables Increase the buffer to prevent stack overflow by fuzz test. The maximum length of the qos configuration buffer is 256 bytes. Currently, the value of the 'val buffer' is only 32 bytes. The sscanf does not check the dest memory length. So the 'val buffer' may stack overflow.
Scope: local
bookworm: resolved (fixed in 6.1.4-1)
bullseye: open
forky: resolved (fixed in 6.1.4-1)
sid: resolved (fixed in 6.1.4-1)
trixie: resolved (fixed in 6.1.4-1)
GHSA
GHSA-h85m-6qg2-23fm: In the Linux kernel, the following vulnerability has been resolved:
crypto: hisilicon/qm - increase the memory of local variables
Increase the buffe
ghsa_unreviewed·2025-09-18
CVE-2022-50407 [MEDIUM] CWE-674 GHSA-h85m-6qg2-23fm: In the Linux kernel, the following vulnerability has been resolved:
crypto: hisilicon/qm - increase the memory of local variables
Increase the buffe
In the Linux kernel, the following vulnerability has been resolved:
crypto: hisilicon/qm - increase the memory of local variables
Increase the buffer to prevent stack overflow by fuzz test. The maximum
length of the qos configuration buffer is 256 bytes. Currently, the value
of the 'val buffer' is only 32 bytes. The sscanf does not check the dest
memory length. So the 'val buffer' may stack overflow.
OSV
CVE-2022-50407: In the Linux kernel, the following vulnerability has been resolved: crypto: hisilicon/qm - increase the memory of local variables Increase the buffer
osv·2025-09-18·CVSS 5.5
CVE-2022-50407 [MEDIUM] CVE-2022-50407: In the Linux kernel, the following vulnerability has been resolved: crypto: hisilicon/qm - increase the memory of local variables Increase the buffer
In the Linux kernel, the following vulnerability has been resolved: crypto: hisilicon/qm - increase the memory of local variables Increase the buffer to prevent stack overflow by fuzz test. The maximum length of the qos configuration buffer is 256 bytes. Currently, the value of the 'val buffer' is only 32 bytes. The sscanf does not check the dest memory length. So the 'val buffer' may stack overflow.
No detection rules found.
No public exploits indexed.
2025-09-18
Published