CVE-2022-50453
published 2025-10-01CVE-2022-50453: In the Linux kernel, the following vulnerability has been resolved: gpiolib: cdev: fix NULL-pointer dereferences There are several places where we can crash…
PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.15%
4.6th percentile
In the Linux kernel, the following vulnerability has been resolved:
gpiolib: cdev: fix NULL-pointer dereferences
There are several places where we can crash the kernel by requesting
lines, unbinding the GPIO device, then calling any of the system calls
relevant to the GPIO character device's annonymous file descriptors:
ioctl(), read(), poll().
While I observed it with the GPIO simulator, it will also happen for any
of the GPIO devices that can be hot-unplugged - for instance any HID GPIO
expander (e.g. CP2112).
This affects both v1 and v2 uAPI.
This fixes it partially by checking if gdev->chip is not NULL but it
doesn't entirely remedy the situation as we still have a race condition
in which another thread can remove the device after the check.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.4-1 (bookworm) | linux 6.1.4-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= d7c51b47ac11e66f547b55640405c1c474642d72 < 6d79546622baab843172b52c3af035f83c1b21df | 6d79546622baab843172b52c3af035f83c1b21df |
| linux | linux | >= d7c51b47ac11e66f547b55640405c1c474642d72 < 7c755a2d6df511eeb5afba966ac28140f9ea5063 | 7c755a2d6df511eeb5afba966ac28140f9ea5063 |
| linux | linux | >= d7c51b47ac11e66f547b55640405c1c474642d72 < d66f68ac9e7ba46b6b90fbe25155723f2126088a | d66f68ac9e7ba46b6b90fbe25155723f2126088a |
| linux | linux | >= d7c51b47ac11e66f547b55640405c1c474642d72 < ac6ce3cd7a3e10a2e37b8970bab81b4d33d5cfc3 | ac6ce3cd7a3e10a2e37b8970bab81b4d33d5cfc3 |
| linux | linux | >= d7c51b47ac11e66f547b55640405c1c474642d72 < 533aae7c94dbc2b14301cfd68ae7e0e90f0c8438 | 533aae7c94dbc2b14301cfd68ae7e0e90f0c8438 |
| linux | linux_kernel | >= 0 < 5.10.178-1 | 5.10.178-1 |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 4.8 < 5.10.163 | 5.10.163 |
| linux | linux_kernel | >= 5.11 < 5.15.86 | 5.15.86 |
| linux | linux_kernel | >= 5.16 < 6.0.16 | 6.0.16 |
| linux | linux_kernel | >= 6.1 < 6.1.2 | 6.1.2 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-c44q-mxrg-grc2: In the Linux kernel, the following vulnerability has been resolved:
gpiolib: cdev: fix NULL-pointer dereferences
There are several places where we c
ghsa_unreviewed·2025-10-01
CVE-2022-50453 [MEDIUM] CWE-476 GHSA-c44q-mxrg-grc2: In the Linux kernel, the following vulnerability has been resolved:
gpiolib: cdev: fix NULL-pointer dereferences
There are several places where we c
In the Linux kernel, the following vulnerability has been resolved:
gpiolib: cdev: fix NULL-pointer dereferences
There are several places where we can crash the kernel by requesting
lines, unbinding the GPIO device, then calling any of the system calls
relevant to the GPIO character device's annonymous file descriptors:
ioctl(), read(), poll().
While I observed it with the GPIO simulator, it will also happen for any
of the GPIO devices that can be hot-unplugged - for instance any HID GPIO
expander (e.g. CP2112).
This affects both v1 and v2 uAPI.
This fixes it partially by checking if gdev->chip is not NULL but it
doesn't entirely remedy the situation as we still have a race condition
in which another thread can remove the device after the check.
OSV
CVE-2022-50453: In the Linux kernel, the following vulnerability has been resolved: gpiolib: cdev: fix NULL-pointer dereferences There are several places where we can
osv·2025-10-01·CVSS 5.5
CVE-2022-50453 [MEDIUM] CVE-2022-50453: In the Linux kernel, the following vulnerability has been resolved: gpiolib: cdev: fix NULL-pointer dereferences There are several places where we can
In the Linux kernel, the following vulnerability has been resolved: gpiolib: cdev: fix NULL-pointer dereferences There are several places where we can crash the kernel by requesting lines, unbinding the GPIO device, then calling any of the system calls relevant to the GPIO character device's annonymous file descriptors: ioctl(), read(), poll(). While I observed it with the GPIO simulator, it will also happen for any of the GPIO devices that can be hot-unplugged - for instance any HID GPIO expander (e.g. CP2112). This affects both v1 and v2 uAPI. This fixes it partially by checking if gdev->chip is not NULL but it doesn't entirely remedy the situation as we still have a race condition in which another thread can remove the device after the check.
Red Hat
kernel: gpiolib: cdev: fix NULL-pointer dereferences
vendor_redhat·2025-10-01·CVSS 5.5
CVE-2022-50453 [MEDIUM] CWE-476 kernel: gpiolib: cdev: fix NULL-pointer dereferences
kernel: gpiolib: cdev: fix NULL-pointer dereferences
In the Linux kernel, the following vulnerability has been resolved:
gpiolib: cdev: fix NULL-pointer dereferences
There are several places where we can crash the kernel by requesting
lines, unbinding the GPIO device, then calling any of the system calls
relevant to the GPIO character device's annonymous file descriptors:
ioctl(), read(), poll().
While I observed it with the GPIO simulator, it will also happen for any
of the GPIO devices that can be hot-unplugged - for instance any HID GPIO
expander (e.g. CP2112).
This affects both v1 and v2 uAPI.
This fixes it partially by checking if gdev->chip is not NULL but it
doesn't entirely remedy the situation as we still have a race condition
in which another thread can remove the device after t
Debian
CVE-2022-50453: linux - In the Linux kernel, the following vulnerability has been resolved: gpiolib: cd...
vendor_debian·2022·CVSS 5.5
CVE-2022-50453 [MEDIUM] CVE-2022-50453: linux - In the Linux kernel, the following vulnerability has been resolved: gpiolib: cd...
In the Linux kernel, the following vulnerability has been resolved: gpiolib: cdev: fix NULL-pointer dereferences There are several places where we can crash the kernel by requesting lines, unbinding the GPIO device, then calling any of the system calls relevant to the GPIO character device's annonymous file descriptors: ioctl(), read(), poll(). While I observed it with the GPIO simulator, it will also happen for any of the GPIO devices that can be hot-unplugged - for instance any HID GPIO expander (e.g. CP2112). This affects both v1 and v2 uAPI. This fixes it partially by checking if gdev->chip is not NULL but it doesn't entirely remedy the situation as we still have a race condition in which another thread can remove the device after the check.
Scope: local
bookworm: resolved (fixed in 6.
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/533aae7c94dbc2b14301cfd68ae7e0e90f0c8438https://git.kernel.org/stable/c/6d79546622baab843172b52c3af035f83c1b21dfhttps://git.kernel.org/stable/c/7c755a2d6df511eeb5afba966ac28140f9ea5063https://git.kernel.org/stable/c/ac6ce3cd7a3e10a2e37b8970bab81b4d33d5cfc3https://git.kernel.org/stable/c/d66f68ac9e7ba46b6b90fbe25155723f2126088a
2025-10-01
Published