CVE-2022-50538NULL Pointer Dereference in Linux

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 97.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 7

Description

In the Linux kernel, the following vulnerability has been resolved: vme: Fix error not catched in fake_init() In fake_init(), __root_device_register() is possible to fail but it's ignored, which can cause unregistering vme_root fail when exit. general protection fault, probably for non-canonical address 0xdffffc000000008c KASAN: null-ptr-deref in range [0x0000000000000460-0x0000000000000467] RIP: 0010:root_device_unregister+0x26/0x60 Call Trace: __x64_sys_delete_module+0x34f/0x540 do_syscall

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages4 packages

NVDlinux/linux_kernel4.94.9.337+7
Debianlinux/linux_kernel< 5.10.178-1+3
CVEListV5linux/linux658bcdae9c6755806e66b33e29d56b33a3ff421ae831fdd60e5863ee03173baf5a0f7c5450b44381+9
debiandebian/linux< linux 6.1.4-1 (bookworm)

Patches

🔴Vulnerability Details

2
GHSA
GHSA-p579-wmgc-72qq: In the Linux kernel, the following vulnerability has been resolved: vme: Fix error not catched in fake_init() In fake_init(), __root_device_register2025-10-07
OSV
CVE-2022-50538: In the Linux kernel, the following vulnerability has been resolved: vme: Fix error not catched in fake_init() In fake_init(), __root_device_register()2025-10-07

📋Vendor Advisories

2
Red Hat
kernel: vme: Fix error not catched in fake_init()2025-10-07
Debian
CVE-2022-50538: linux - In the Linux kernel, the following vulnerability has been resolved: vme: Fix er...2022