cbcvebase.
CVE-2022-50733
published 2025-12-24

CVE-2022-50733: In the Linux kernel, the following vulnerability has been resolved: usb: idmouse: fix an uninit-value in idmouse_open In idmouse_create_image, if any…

PriorityP422low5.5
EPSS
0.25%
16.1th percentile
In the Linux kernel, the following vulnerability has been resolved: usb: idmouse: fix an uninit-value in idmouse_open In idmouse_create_image, if any ftip_command fails, it will go to the reset label. However, this leads to the data in bulk_in_buffer[HEADER..IMGSIZE] uninitialized. And the check for valid image incurs an uninitialized dereference. Fix this by moving the check before reset label since this check only be valid if the data after bulk_in_buffer[HEADER] has concrete data. Note that this is found by KMSAN, so only kernel compilation is tested.

Affected

23 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.0.3-1 (bookworm)linux 6.0.3-1 (bookworm)
linuxlinux
linuxlinux>= 4244f72436ab77c3c29a6447af81734ab3925d85 < b3304a6df957cc89a0590cb505388d659bf3db4cb3304a6df957cc89a0590cb505388d659bf3db4c
linuxlinux>= 4244f72436ab77c3c29a6447af81734ab3925d85 < 7dad42032f68718259590b0cc7654e9a95ff97627dad42032f68718259590b0cc7654e9a95ff9762
linuxlinux>= 4244f72436ab77c3c29a6447af81734ab3925d85 < f589b667567fde4f81d6e6c40f42b9f2224690eaf589b667567fde4f81d6e6c40f42b9f2224690ea
linuxlinux>= 4244f72436ab77c3c29a6447af81734ab3925d85 < 1eae30c0113dde7522088231584d62415011a0351eae30c0113dde7522088231584d62415011a035
linuxlinux>= 4244f72436ab77c3c29a6447af81734ab3925d85 < b8bbae3236ab7dccc66c42bc3f7cdbcfc0786e54b8bbae3236ab7dccc66c42bc3f7cdbcfc0786e54
linuxlinux>= 4244f72436ab77c3c29a6447af81734ab3925d85 < 20b8c456df584ebb2387dc23d40ebe4ff334417c20b8c456df584ebb2387dc23d40ebe4ff334417c
linuxlinux>= 4244f72436ab77c3c29a6447af81734ab3925d85 < 6163a5ae097bc78fa26c243fb384537e25610fd76163a5ae097bc78fa26c243fb384537e25610fd7
linuxlinux>= 4244f72436ab77c3c29a6447af81734ab3925d85 < adad163d1cff248a5df9f7cec50158e6ca89f33badad163d1cff248a5df9f7cec50158e6ca89f33b
linuxlinux>= 4244f72436ab77c3c29a6447af81734ab3925d85 < bce2b0539933e485d22d6f6f076c0fcd6f185c4cbce2b0539933e485d22d6f6f076c0fcd6f185c4c
linuxlinux_kernel>= 0 < 5.10.158-15.10.158-1
linuxlinux_kernel>= 0 < 6.0.3-16.0.3-1
linuxlinux_kernel>= 0 < 6.0.3-16.0.3-1
linuxlinux_kernel>= 0 < 6.0.3-16.0.3-1
linuxlinux_kernel>= 2.6.13 < 4.9.3314.9.331
linuxlinux_kernel>= 4.10.0 < 4.14.2964.14.296
linuxlinux_kernel>= 4.15.0 < 4.19.2624.19.262
linuxlinux_kernel>= 4.20.0 < 5.4.2205.4.220
linuxlinux_kernel>= 5.11.0 < 5.15.755.15.75
linuxlinux_kernel>= 5.16.0 < 5.19.175.19.17
linuxlinux_kernel>= 5.20.0 < 6.0.36.0.3
linuxlinux_kernel>= 5.5.0 < 5.10.1505.10.150
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.