CVE-2022-50652
published 2025-12-09CVE-2022-50652: In the Linux kernel, the following vulnerability has been resolved: uio: uio_dmem_genirq: Fix missing unlock in irq configuration Commit b74351287d4b ("uio…
PriorityP424
EPSS
0.21%
11.0th percentile
In the Linux kernel, the following vulnerability has been resolved:
uio: uio_dmem_genirq: Fix missing unlock in irq configuration
Commit b74351287d4b ("uio: fix a sleep-in-atomic-context bug in
uio_dmem_genirq_irqcontrol()") started calling disable_irq() without
holding the spinlock because it can sleep. However, that fix introduced
another bug: if interrupt is already disabled and a new disable request
comes in, then the spinlock is not unlocked:
root@localhost:~# printf '\x00\x00\x00\x00' > /dev/uio0
root@localhost:~# printf '\x00\x00\x00\x00' > /dev/uio0
root@localhost:~# [ 14.851538] BUG: scheduling while atomic: bash/223/0x00000002
[ 14.851991] Modules linked in: uio_dmem_genirq uio myfpga(OE) bochs drm_vram_helper drm_ttm_helper ttm drm_kms_helper drm snd_pcm ppdev joydev psmouse snd_timer snd e1000fb_sys_fops syscopyarea parport sysfillrect soundcore sysimgblt input_leds pcspkr i2c_piix4 serio_raw floppy evbug qemu_fw_cfg mac_hid pata_acpi ip_tables x_tables autofs4 [last unloaded: parport_pc]
[ 14.854206] CPU: 0 PID: 223 Comm: bash Tainted: G OE 6.0.0-rc7 #21
[ 14.854786] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.0-0-gd239552ce722-prebuilt.qemu.org 04/01/2014
[ 14.855664] Call Trace:
[ 14.855861]
[ 14.856025] dump_stack_lvl+0x4d/0x67
[ 14.856325] dump_stack+0x14/0x1a
[ 14.856583] __schedule_bug.cold+0x4b/0x5c
[ 14.856915] __schedule+0xe81/0x13d0
[ 14.857199] ? idr_find+0x13/0x20
[ 14.857456] ? get_work_pool+0x2d/0x50
[ 14.857756] ? __flush_work+0x233/0x280
[ 14.858068] ? __schedule+0xa95/0x13d0
[ 14.858307] ? idr_find+0x13/0x20
[ 14.858519] ? get_work_pool+0x2d/0x50
[ 14.858798] schedule+0x6c/0x100
[ 14.859009] schedule_hrtimeout_range_clock+0xff/0x110
[ 14.859335] ? tty_write_room+0x1f/0x30
[ 14.859598] ? n_tty_poll+0x1ec/0x220
[ 14.859830] ? tty_ldisc_deref+0x1a/0x20
[ 14.860090] schedule_hrtimeout_range+0x17/0x20
[ 14.860373] do_select+0x596/0x840
[ 14.860627] ? __kernel_text_address+0x16/0x50
[ 14.860954] ? poll_freewait+0xb
Affected
31 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.4-1 (bookworm) | linux 6.1.4-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | >= 0151b03f43f2d295a6949454434074b34a262e06 < a323d24a0183be730d2398b11b3a91e5c2e222a0 | a323d24a0183be730d2398b11b3a91e5c2e222a0 |
| linux | linux | >= 4.14.172 < 4.14.303 | 4.14.303 |
| linux | linux | >= 4.19.106 < 4.19.270 | 4.19.270 |
| linux | linux | >= 4.4.215 < 4.5 | 4.5 |
| linux | linux | >= 4.9.215 < 4.9.337 | 4.9.337 |
| linux | linux | >= 5.4.22 < 5.4.229 | 5.4.229 |
| linux | linux | >= 5.5.6 < 5.6 | 5.6 |
| linux | linux | >= 750a95d63746458e86c6d92dfad48a05c64d0ecd < eca77a25a7cb3201738f4b55b9b8fa1089d7d002 | eca77a25a7cb3201738f4b55b9b8fa1089d7d002 |
| linux | linux | >= b74351287d4bd90636c3f48bc188c2f53824c2d4 < 9bf7a0b2b15cd12e15f7858072bd89933746de67 | 9bf7a0b2b15cd12e15f7858072bd89933746de67 |
| linux | linux | >= b74351287d4bd90636c3f48bc188c2f53824c2d4 < 79a4bdb6b9920134af1a4738a1fa36a0438cd905 | 79a4bdb6b9920134af1a4738a1fa36a0438cd905 |
| linux | linux | >= b74351287d4bd90636c3f48bc188c2f53824c2d4 < 030b6c7bb1e4edebaee2b1e48fbcc9cd5998d51d | 030b6c7bb1e4edebaee2b1e48fbcc9cd5998d51d |
| linux | linux | >= b74351287d4bd90636c3f48bc188c2f53824c2d4 < ee180e867ce4b2f744799247b81050b3e5dd62cd | ee180e867ce4b2f744799247b81050b3e5dd62cd |
| linux | linux | >= b74351287d4bd90636c3f48bc188c2f53824c2d4 < 9de255c461d1b3f0242b3ad1450c3323a3e00b34 | 9de255c461d1b3f0242b3ad1450c3323a3e00b34 |
| linux | linux | >= b77fa964ecb1d72a671234f5bea95b41f77c233a < 9977cb7af5a8f4738198b020436e2e56c5cd721e | 9977cb7af5a8f4738198b020436e2e56c5cd721e |
| linux | linux | >= ea6b7b1d58790ffb36bace723f6e62a1c8595c77 < ac5585bb06a2e82177269bee93e59887ce591106 | ac5585bb06a2e82177269bee93e59887ce591106 |
| linux | linux_kernel | >= 0 < 5.10.178-1 | 5.10.178-1 |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 0 < 4.9.337 | 4.9.337 |
| linux | linux_kernel | >= 4.10.0 < 4.14.303 | 4.14.303 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7863-hf67-mmwv: In the Linux kernel, the following vulnerability has been resolved:
uio: uio_dmem_genirq: Fix missing unlock in irq configuration
Commit b74351287d4
ghsa_unreviewed·2025-12-09
CVE-2022-50652 GHSA-7863-hf67-mmwv: In the Linux kernel, the following vulnerability has been resolved:
uio: uio_dmem_genirq: Fix missing unlock in irq configuration
Commit b74351287d4
In the Linux kernel, the following vulnerability has been resolved:
uio: uio_dmem_genirq: Fix missing unlock in irq configuration
Commit b74351287d4b ("uio: fix a sleep-in-atomic-context bug in
uio_dmem_genirq_irqcontrol()") started calling disable_irq() without
holding the spinlock because it can sleep. However, that fix introduced
another bug: if interrupt is already disabled and a new disable request
comes in, then the spinlock is not unlocked:
root@localhost:~# printf '\x00\x00\x00\x00' > /dev/uio0
root@localhost:~# printf '\x00\x00\x00\x00' > /dev/uio0
root@localhost:~# [ 14.851538] BUG: scheduling while atomic: bash/223/0x00000002
[ 14.851991] Modules linked in: uio_dmem_genirq uio myfpga(OE) bochs drm_vram_helper drm_ttm_helper ttm drm_kms_helper drm snd_pcm ppdev joydev psmouse
OSV
CVE-2022-50652: In the Linux kernel, the following vulnerability has been resolved: uio: uio_dmem_genirq: Fix missing unlock in irq configuration Commit b74351287d4b
osv·2025-12-09
CVE-2022-50652 CVE-2022-50652: In the Linux kernel, the following vulnerability has been resolved: uio: uio_dmem_genirq: Fix missing unlock in irq configuration Commit b74351287d4b
In the Linux kernel, the following vulnerability has been resolved: uio: uio_dmem_genirq: Fix missing unlock in irq configuration Commit b74351287d4b ("uio: fix a sleep-in-atomic-context bug in uio_dmem_genirq_irqcontrol()") started calling disable_irq() without holding the spinlock because it can sleep. However, that fix introduced another bug: if interrupt is already disabled and a new disable request comes in, then the spinlock is not unlocked: root@localhost:~# printf '\x00\x00\x00\x00' > /dev/uio0 root@localhost:~# printf '\x00\x00\x00\x00' > /dev/uio0 root@localhost:~# [ 14.851538] BUG: scheduling while atomic: bash/223/0x00000002 [ 14.851991] Modules linked in: uio_dmem_genirq uio myfpga(OE) bochs drm_vram_helper drm_ttm_helper ttm drm_kms_helper drm snd_pcm ppdev joydev psmouse snd
OSV
uio: uio_dmem_genirq: Fix missing unlock in irq configuration
osv·2025-12-09
CVE-2022-50652 uio: uio_dmem_genirq: Fix missing unlock in irq configuration
uio: uio_dmem_genirq: Fix missing unlock in irq configuration
In the Linux kernel, the following vulnerability has been resolved:
uio: uio_dmem_genirq: Fix missing unlock in irq configuration
Commit b74351287d4b ("uio: fix a sleep-in-atomic-context bug in
uio_dmem_genirq_irqcontrol()") started calling disable_irq() without
holding the spinlock because it can sleep. However, that fix introduced
another bug: if interrupt is already disabled and a new disable request
comes in, then the spinlock is not unlocked:
root@localhost:~# printf '\x00\x00\x00\x00' > /dev/uio0
root@localhost:~# printf '\x00\x00\x00\x00' > /dev/uio0
root@localhost:~# [ 14.851538] BUG: scheduling while atomic: bash/223/0x00000002
[ 14.851991] Modules linked in: uio_dmem_genirq uio myfpga(OE) bochs drm_vram_helper drm_
Red Hat
kernel: uio: uio_dmem_genirq: Fix missing unlock in irq configuration
vendor_redhat·2025-12-09
CVE-2022-50652 kernel: uio: uio_dmem_genirq: Fix missing unlock in irq configuration
kernel: uio: uio_dmem_genirq: Fix missing unlock in irq configuration
In the Linux kernel, the following vulnerability has been resolved:
uio: uio_dmem_genirq: Fix missing unlock in irq configuration
Commit b74351287d4b ("uio: fix a sleep-in-atomic-context bug in
uio_dmem_genirq_irqcontrol()") started calling disable_irq() without
holding the spinlock because it can sleep. However, that fix introduced
another bug: if interrupt is already disabled and a new disable request
comes in, then the spinlock is not unlocked:
root@localhost:~# printf '\x00\x00\x00\x00' > /dev/uio0
root@localhost:~# printf '\x00\x00\x00\x00' > /dev/uio0
root@localhost:~# [ 14.851538] BUG: scheduling while atomic: bash/223/0x00000002
[ 14.851991] Modules linked in: uio_dmem_genirq uio myfpga(OE) bochs drm_vram_helper
Debian
CVE-2022-50652: linux - In the Linux kernel, the following vulnerability has been resolved: uio: uio_dm...
vendor_debian·2022
CVE-2022-50652 CVE-2022-50652: linux - In the Linux kernel, the following vulnerability has been resolved: uio: uio_dm...
In the Linux kernel, the following vulnerability has been resolved: uio: uio_dmem_genirq: Fix missing unlock in irq configuration Commit b74351287d4b ("uio: fix a sleep-in-atomic-context bug in uio_dmem_genirq_irqcontrol()") started calling disable_irq() without holding the spinlock because it can sleep. However, that fix introduced another bug: if interrupt is already disabled and a new disable request comes in, then the spinlock is not unlocked: root@localhost:~# printf '\x00\x00\x00\x00' > /dev/uio0 root@localhost:~# printf '\x00\x00\x00\x00' > /dev/uio0 root@localhost:~# [ 14.851538] BUG: scheduling while atomic: bash/223/0x00000002 [ 14.851991] Modules linked in: uio_dmem_genirq uio myfpga(OE) bochs drm_vram_helper drm_ttm_helper ttm drm_kms_helper drm snd_pcm ppdev joydev psmouse snd
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/030b6c7bb1e4edebaee2b1e48fbcc9cd5998d51dhttps://git.kernel.org/stable/c/79a4bdb6b9920134af1a4738a1fa36a0438cd905https://git.kernel.org/stable/c/9977cb7af5a8f4738198b020436e2e56c5cd721ehttps://git.kernel.org/stable/c/9bf7a0b2b15cd12e15f7858072bd89933746de67https://git.kernel.org/stable/c/9de255c461d1b3f0242b3ad1450c3323a3e00b34https://git.kernel.org/stable/c/a323d24a0183be730d2398b11b3a91e5c2e222a0https://git.kernel.org/stable/c/ac5585bb06a2e82177269bee93e59887ce591106https://git.kernel.org/stable/c/eca77a25a7cb3201738f4b55b9b8fa1089d7d002https://git.kernel.org/stable/c/ee180e867ce4b2f744799247b81050b3e5dd62cd
2025-12-09
Published