cbcvebase.
CVE-2022-50625
published 2025-12-08

CVE-2022-50625: In the Linux kernel, the following vulnerability has been resolved: serial: amba-pl011: avoid SBSA UART accessing DMACR register Chapter "B Generic UART" in…

PriorityP425medium5.8
EPSS
0.21%
11.5th percentile
In the Linux kernel, the following vulnerability has been resolved: serial: amba-pl011: avoid SBSA UART accessing DMACR register Chapter "B Generic UART" in "ARM Server Base System Architecture" [1] documentation describes a generic UART interface. Such generic UART does not support DMA. In current code, sbsa_uart_pops and amba_pl011_pops share the same stop_rx operation, which will invoke pl011_dma_rx_stop, leading to an access of the DMACR register. This commit adds a using_rx_dma check in pl011_dma_rx_stop to avoid the access to DMACR register for SBSA UARTs which does not support DMA. When the kernel enables DMA engine with "CONFIG_DMA_ENGINE=y", Linux SBSA PL011 driver will access PL011 DMACR register in some functions. For most real SBSA Pl011 hardware implementations, the DMACR write behaviour will be ignored. So these DMACR operations will not cause obvious problems. But for some virtual SBSA PL011 hardware, like Xen virtual SBSA PL011 (vpl011) device, the behaviour might be different. Xen vpl011 emulation will inject a data abort to guest, when guest is accessing an unimplemented UART register. As Xen VPL011 is SBSA compatible, it will not implement DMACR register. So when Linux SBSA PL011 driver access DMACR register, it will get an unhandled data abort fault and the application will get a segmentation fault: Unhandled fault at 0xffffffc00944d048 Mem abort info: ESR = 0x96000000 EC = 0x25: DABT (current EL), IL = 32 bits SET = 0, FnV = 0 EA = 0, S1PTW = 0 FSC = 0x00: ttbr address size fault Data abort info: ISV = 0, ISS = 0x00000000 CM = 0, WnR = 0 swapper pgtable: 4k pages, 39-bit VAs, pgdp=0000000020e2e000 [ffffffc00944d048] pgd=100000003ffff803, p4d=100000003ffff803, pud=100000003ffff803, pmd=100000003fffa803, pte=006800009c090f13 Internal error: ttbr address size fault: 96000000 [#1] PREEMPT SMP ... Call trace: pl011_stop_rx+0x70/0x80 tty_port_shutdown+0x7c/0xb4 tty_port_close+0x60/0xcc uart_close+0x34/0x8c tty_release+0x144/0x4c0 __fput+0x78/0x220

Affected

23 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.4-1 (bookworm)linux 6.1.4-1 (bookworm)
linuxlinux
linuxlinux>= 0dd1e247fd39aed20fd2baacc62ca44d82534798 < 1c5f0d3f480abd8c26761b6b1f486822e77faea31c5f0d3f480abd8c26761b6b1f486822e77faea3
linuxlinux>= 0dd1e247fd39aed20fd2baacc62ca44d82534798 < a4ea20ab82aa2b197dc7b08f51e1d615578276a0a4ea20ab82aa2b197dc7b08f51e1d615578276a0
linuxlinux>= 0dd1e247fd39aed20fd2baacc62ca44d82534798 < 78d837ce20517e0c1ff3ebe08ad64636e02c2e4878d837ce20517e0c1ff3ebe08ad64636e02c2e48
linuxlinux>= 0dd1e247fd39aed20fd2baacc62ca44d82534798 < 965f07ea5fd1b9591bcccc825a93ad883e56222c965f07ea5fd1b9591bcccc825a93ad883e56222c
linuxlinux>= 0dd1e247fd39aed20fd2baacc62ca44d82534798 < d5b16eb076f46c88d02d41ece5bec4e0d89158bbd5b16eb076f46c88d02d41ece5bec4e0d89158bb
linuxlinux>= 0dd1e247fd39aed20fd2baacc62ca44d82534798 < d71a611fca1984c0765f9317ff471ac8cd0e3e2fd71a611fca1984c0765f9317ff471ac8cd0e3e2f
linuxlinux>= 0dd1e247fd39aed20fd2baacc62ca44d82534798 < 38a10fdd54d17590d45cb1c43b9889da383b6b1a38a10fdd54d17590d45cb1c43b9889da383b6b1a
linuxlinux>= 0dd1e247fd39aed20fd2baacc62ca44d82534798 < 64bc5dbc3260230e2f022288c71e5c680059384a64bc5dbc3260230e2f022288c71e5c680059384a
linuxlinux>= 0dd1e247fd39aed20fd2baacc62ca44d82534798 < 94cdb9f33698478b0e7062586633c42c6158a78694cdb9f33698478b0e7062586633c42c6158a786
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 4.10.0 < 4.14.3034.14.303
linuxlinux_kernel>= 4.15.0 < 4.19.2704.19.270
linuxlinux_kernel>= 4.2.0 < 4.9.3374.9.337
linuxlinux_kernel>= 4.20.0 < 5.4.2295.4.229
linuxlinux_kernel>= 5.11.0 < 5.15.865.15.86
linuxlinux_kernel>= 5.16.0 < 6.0.166.0.16
linuxlinux_kernel>= 5.5.0 < 5.10.1635.10.163
linuxlinux_kernel>= 6.1.0 < 6.1.26.1.2
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.