CVE-2022-50721
published 2025-12-24CVE-2022-50721: In the Linux kernel, the following vulnerability has been resolved: dmaengine: qcom-adm: fix wrong calling convention for prep_slave_sg The calling convention…
PriorityP420medium5.1
EPSS
0.21%
10.8th percentile
In the Linux kernel, the following vulnerability has been resolved:
dmaengine: qcom-adm: fix wrong calling convention for prep_slave_sg
The calling convention for pre_slave_sg is to return NULL on error and
provide an error log to the system. Qcom-adm instead provide error
pointer when an error occur. This indirectly cause kernel panic for
example for the nandc driver that checks only if the pointer returned by
device_prep_slave_sg is not NULL. Returning an error pointer makes nandc
think the device_prep_slave_sg function correctly completed and makes
the kernel panics later in the code.
While nandc is the one that makes the kernel crash, it was pointed out
that the real problem is qcom-adm not following calling convention for
that function.
To fix this, drop returning error pointer and return NULL with an error
log.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.0.3-1 (bookworm) | linux 6.0.3-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 5c9f8c2dbdbe53818bcde6aa6695e1331e5f841f < 5653bd0200944e5803fa8e32dc36aa49931312f9 | 5653bd0200944e5803fa8e32dc36aa49931312f9 |
| linux | linux | >= 5c9f8c2dbdbe53818bcde6aa6695e1331e5f841f < 9a041174c58a226e713f6cebd41eccec7a5cfa72 | 9a041174c58a226e713f6cebd41eccec7a5cfa72 |
| linux | linux | >= 5c9f8c2dbdbe53818bcde6aa6695e1331e5f841f < b9d2140c3badf4107973ad77c5a0ec3075705c85 | b9d2140c3badf4107973ad77c5a0ec3075705c85 |
| linux | linux_kernel | >= 0 < 6.0.3-1 | 6.0.3-1 |
| linux | linux_kernel | >= 0 < 6.0.3-1 | 6.0.3-1 |
| linux | linux_kernel | >= 0 < 6.0.3-1 | 6.0.3-1 |
| linux | linux_kernel | >= 5.11.0 < 5.19.17 | 5.19.17 |
| linux | linux_kernel | >= 5.20.0 < 6.0.3 | 6.0.3 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: dmaengine: qcom-adm: fix wrong calling convention for prep_slave_sg
vendor_redhat·2025-12-24·CVSS 5.1
CVE-2022-50721 [MEDIUM] CWE-209 kernel: dmaengine: qcom-adm: fix wrong calling convention for prep_slave_sg
kernel: dmaengine: qcom-adm: fix wrong calling convention for prep_slave_sg
In the Linux kernel, the following vulnerability has been resolved:
dmaengine: qcom-adm: fix wrong calling convention for prep_slave_sg
The calling convention for pre_slave_sg is to return NULL on error and
provide an error log to the system. Qcom-adm instead provide error
pointer when an error occur. This indirectly cause kernel panic for
example for the nandc driver that checks only if the pointer returned by
device_prep_slave_sg is not NULL. Returning an error pointer makes nandc
think the device_prep_slave_sg function correctly completed and makes
the kernel panics later in the code.
While nandc is the one that makes the kernel crash, it was pointed out
that the real problem is qcom-adm not following calling c
Debian
CVE-2022-50721: linux - In the Linux kernel, the following vulnerability has been resolved: dmaengine: ...
vendor_debian·2022
CVE-2022-50721 CVE-2022-50721: linux - In the Linux kernel, the following vulnerability has been resolved: dmaengine: ...
In the Linux kernel, the following vulnerability has been resolved: dmaengine: qcom-adm: fix wrong calling convention for prep_slave_sg The calling convention for pre_slave_sg is to return NULL on error and provide an error log to the system. Qcom-adm instead provide error pointer when an error occur. This indirectly cause kernel panic for example for the nandc driver that checks only if the pointer returned by device_prep_slave_sg is not NULL. Returning an error pointer makes nandc think the device_prep_slave_sg function correctly completed and makes the kernel panics later in the code. While nandc is the one that makes the kernel crash, it was pointed out that the real problem is qcom-adm not following calling convention for that function. To fix this, drop returning error pointer and re
VulDB
Linux Kernel up to 5.19.16/6.0.2 dmaengine device_prep_slave_sg denial of service (Nessus ID 279873 / WID-SEC-2025-2929)
vuldb·2026-04-21
CVE-2022-50721 [CRITICAL] Linux Kernel up to 5.19.16/6.0.2 dmaengine device_prep_slave_sg denial of service (Nessus ID 279873 / WID-SEC-2025-2929)
A vulnerability classified as critical was found in Linux Kernel up to 5.19.16/6.0.2. Affected is the function device_prep_slave_sg of the component dmaengine. The manipulation results in denial of service.
This vulnerability is cataloged as CVE-2022-50721. The attack must originate from the local network. There is no exploit available.
Upgrading the affected component is advised.
GHSA
GHSA-9gcm-5rwh-p2jv: In the Linux kernel, the following vulnerability has been resolved:
dmaengine: qcom-adm: fix wrong calling convention for prep_slave_sg
The calling
ghsa_unreviewed·2025-12-24
CVE-2022-50721 GHSA-9gcm-5rwh-p2jv: In the Linux kernel, the following vulnerability has been resolved:
dmaengine: qcom-adm: fix wrong calling convention for prep_slave_sg
The calling
In the Linux kernel, the following vulnerability has been resolved:
dmaengine: qcom-adm: fix wrong calling convention for prep_slave_sg
The calling convention for pre_slave_sg is to return NULL on error and
provide an error log to the system. Qcom-adm instead provide error
pointer when an error occur. This indirectly cause kernel panic for
example for the nandc driver that checks only if the pointer returned by
device_prep_slave_sg is not NULL. Returning an error pointer makes nandc
think the device_prep_slave_sg function correctly completed and makes
the kernel panics later in the code.
While nandc is the one that makes the kernel crash, it was pointed out
that the real problem is qcom-adm not following calling convention for
that function.
To fix this, drop returning error pointer an
OSV
dmaengine: qcom-adm: fix wrong calling convention for prep_slave_sg
osv·2025-12-24
CVE-2022-50721 dmaengine: qcom-adm: fix wrong calling convention for prep_slave_sg
dmaengine: qcom-adm: fix wrong calling convention for prep_slave_sg
In the Linux kernel, the following vulnerability has been resolved:
dmaengine: qcom-adm: fix wrong calling convention for prep_slave_sg
The calling convention for pre_slave_sg is to return NULL on error and
provide an error log to the system. Qcom-adm instead provide error
pointer when an error occur. This indirectly cause kernel panic for
example for the nandc driver that checks only if the pointer returned by
device_prep_slave_sg is not NULL. Returning an error pointer makes nandc
think the device_prep_slave_sg function correctly completed and makes
the kernel panics later in the code.
While nandc is the one that makes the kernel crash, it was pointed out
that the real problem is qcom-adm not following calling conven
OSV
CVE-2022-50721: In the Linux kernel, the following vulnerability has been resolved: dmaengine: qcom-adm: fix wrong calling convention for prep_slave_sg The calling co
osv·2025-12-24
CVE-2022-50721 CVE-2022-50721: In the Linux kernel, the following vulnerability has been resolved: dmaengine: qcom-adm: fix wrong calling convention for prep_slave_sg The calling co
In the Linux kernel, the following vulnerability has been resolved: dmaengine: qcom-adm: fix wrong calling convention for prep_slave_sg The calling convention for pre_slave_sg is to return NULL on error and provide an error log to the system. Qcom-adm instead provide error pointer when an error occur. This indirectly cause kernel panic for example for the nandc driver that checks only if the pointer returned by device_prep_slave_sg is not NULL. Returning an error pointer makes nandc think the device_prep_slave_sg function correctly completed and makes the kernel panics later in the code. While nandc is the one that makes the kernel crash, it was pointed out that the real problem is qcom-adm not following calling convention for that function. To fix this, drop returning error pointer and re
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2022-50721 kernel: dmaengine: qcom-adm: fix wrong calling convention for prep_slave_sg
bugzilla·2025-12-24
CVE-2022-50721 [MEDIUM] CVE-2022-50721 kernel: dmaengine: qcom-adm: fix wrong calling convention for prep_slave_sg
CVE-2022-50721 kernel: dmaengine: qcom-adm: fix wrong calling convention for prep_slave_sg
In the Linux kernel, the following vulnerability has been resolved:
dmaengine: qcom-adm: fix wrong calling convention for prep_slave_sg
The calling convention for pre_slave_sg is to return NULL on error and
provide an error log to the system. Qcom-adm instead provide error
pointer when an error occur. This indirectly cause kernel panic for
example for the nandc driver that checks only if the pointer returned by
device_prep_slave_sg is not NULL. Returning an error pointer makes nandc
think the device_prep_slave_sg function correctly completed and makes
the kernel panics later in the code.
While nandc is the one that makes the kernel crash, it was pointed out
that the real problem is qcom-adm not f
Wiz
CVE-2022-50721 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
CVE-2022-50721 CVE-2022-50721 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2022-50721 :
Linux Kernel vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
dmaengine: qcom-adm: fix wrong calling convention for prep_slave_sg
The calling convention for pre_slave_sg is to return NULL on error and
provide an error log to the system. Qcom-adm instead provide error
pointer when an error occur. This indirectly cause kernel panic for
example for the nandc driver that checks only if the pointer returned by
device_prep_slave_sg is not NULL. Returning an error pointer makes nandc
think the device_prep_slave_sg function correctly completed and makes
the kernel panics later in the code.
While nandc is the one that makes the kernel crash, it was pointed out
that the real problem is qcom-adm not following calling co
2025-12-24
Published