CVE-2022-50847
published 2025-12-30CVE-2022-50847: In the Linux kernel, the following vulnerability has been resolved: drm/bridge: it6505: Initialize AUX channel in it6505_i2c_probe During device boot, the HPD…
PriorityP421low4.7
EPSS
0.21%
10.7th percentile
In the Linux kernel, the following vulnerability has been resolved:
drm/bridge: it6505: Initialize AUX channel in it6505_i2c_probe
During device boot, the HPD interrupt could be triggered before the DRM
subsystem registers it6505 as a DRM bridge. In such cases, the driver
tries to access AUX channel and causes NULL pointer dereference.
Initializing the AUX channel earlier to prevent such error.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.4-1 (bookworm) | linux 6.1.4-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= b5c84a9edcd418cd055becad6a22439e7c5e3bf8 < 8ed8505803774fc3f36a432718036c21cc51e2ba | 8ed8505803774fc3f36a432718036c21cc51e2ba |
| linux | linux | >= b5c84a9edcd418cd055becad6a22439e7c5e3bf8 < 172d4d64075075f955e6e416915e3f287eec514a | 172d4d64075075f955e6e416915e3f287eec514a |
| linux | linux | >= b5c84a9edcd418cd055becad6a22439e7c5e3bf8 < e577d4b13064c337b83fe7edecb3f34e87144821 | e577d4b13064c337b83fe7edecb3f34e87144821 |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 5.18.0 < 6.0.16 | 6.0.16 |
| linux | linux_kernel | >= 6.1.0 < 6.1.2 | 6.1.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Linux Kernel up to 6.0.15/6.1.1 it6505_i2c_probe null pointer dereference (WID-SEC-2025-2941)
vuldb·2026-04-26
CVE-2022-50847 [CRITICAL] Linux Kernel up to 6.0.15/6.1.1 it6505_i2c_probe null pointer dereference (WID-SEC-2025-2941)
A vulnerability described as critical has been identified in Linux Kernel up to 6.0.15/6.1.1. Affected by this issue is the function it6505_i2c_probe. Executing a manipulation can lead to null pointer dereference.
This vulnerability is tracked as CVE-2022-50847. The attack is only possible within the local network. No exploit exists.
Upgrading the affected component is recommended.
OSV
drm/bridge: it6505: Initialize AUX channel in it6505_i2c_probe
osv·2025-12-30
CVE-2022-50847 drm/bridge: it6505: Initialize AUX channel in it6505_i2c_probe
drm/bridge: it6505: Initialize AUX channel in it6505_i2c_probe
In the Linux kernel, the following vulnerability has been resolved:
drm/bridge: it6505: Initialize AUX channel in it6505_i2c_probe
During device boot, the HPD interrupt could be triggered before the DRM
subsystem registers it6505 as a DRM bridge. In such cases, the driver
tries to access AUX channel and causes NULL pointer dereference.
Initializing the AUX channel earlier to prevent such error.
OSV
CVE-2022-50847: In the Linux kernel, the following vulnerability has been resolved: drm/bridge: it6505: Initialize AUX channel in it6505_i2c_probe During device boot,
osv·2025-12-30
CVE-2022-50847 CVE-2022-50847: In the Linux kernel, the following vulnerability has been resolved: drm/bridge: it6505: Initialize AUX channel in it6505_i2c_probe During device boot,
In the Linux kernel, the following vulnerability has been resolved: drm/bridge: it6505: Initialize AUX channel in it6505_i2c_probe During device boot, the HPD interrupt could be triggered before the DRM subsystem registers it6505 as a DRM bridge. In such cases, the driver tries to access AUX channel and causes NULL pointer dereference. Initializing the AUX channel earlier to prevent such error.
GHSA
GHSA-78f2-hq34-889m: In the Linux kernel, the following vulnerability has been resolved:
drm/bridge: it6505: Initialize AUX channel in it6505_i2c_probe
During device boo
ghsa_unreviewed·2025-12-30
CVE-2022-50847 GHSA-78f2-hq34-889m: In the Linux kernel, the following vulnerability has been resolved:
drm/bridge: it6505: Initialize AUX channel in it6505_i2c_probe
During device boo
In the Linux kernel, the following vulnerability has been resolved:
drm/bridge: it6505: Initialize AUX channel in it6505_i2c_probe
During device boot, the HPD interrupt could be triggered before the DRM
subsystem registers it6505 as a DRM bridge. In such cases, the driver
tries to access AUX channel and causes NULL pointer dereference.
Initializing the AUX channel earlier to prevent such error.
Red Hat
kernel: drm/bridge: it6505: Initialize AUX channel in it6505_i2c_probe
vendor_redhat·2025-12-30·CVSS 4.7
CVE-2022-50847 [LOW] CWE-824 kernel: drm/bridge: it6505: Initialize AUX channel in it6505_i2c_probe
kernel: drm/bridge: it6505: Initialize AUX channel in it6505_i2c_probe
In the Linux kernel, the following vulnerability has been resolved:
drm/bridge: it6505: Initialize AUX channel in it6505_i2c_probe
During device boot, the HPD interrupt could be triggered before the DRM
subsystem registers it6505 as a DRM bridge. In such cases, the driver
tries to access AUX channel and causes NULL pointer dereference.
Initializing the AUX channel earlier to prevent such error.
A NULL pointer dereference was found in the IT6505 DisplayPort bridge driver. If an HPD interrupt fires before the DRM bridge registration completes, the driver attempts to access an uninitialized AUX channel, causing a kernel crash.
Statement: This affects systems using IT6505 DisplayPort bridges with specific timing conditio
Debian
CVE-2022-50847: linux - In the Linux kernel, the following vulnerability has been resolved: drm/bridge:...
vendor_debian·2022
CVE-2022-50847 CVE-2022-50847: linux - In the Linux kernel, the following vulnerability has been resolved: drm/bridge:...
In the Linux kernel, the following vulnerability has been resolved: drm/bridge: it6505: Initialize AUX channel in it6505_i2c_probe During device boot, the HPD interrupt could be triggered before the DRM subsystem registers it6505 as a DRM bridge. In such cases, the driver tries to access AUX channel and causes NULL pointer dereference. Initializing the AUX channel earlier to prevent such error.
Scope: local
bookworm: resolved (fixed in 6.1.4-1)
bullseye: resolved
forky: resolved (fixed in 6.1.4-1)
sid: resolved (fixed in 6.1.4-1)
trixie: resolved (fixed in 6.1.4-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2022-50847 kernel: drm/bridge: it6505: Initialize AUX channel in it6505_i2c_probe
bugzilla·2025-12-30
CVE-2022-50847 [LOW] CVE-2022-50847 kernel: drm/bridge: it6505: Initialize AUX channel in it6505_i2c_probe
CVE-2022-50847 kernel: drm/bridge: it6505: Initialize AUX channel in it6505_i2c_probe
In the Linux kernel, the following vulnerability has been resolved:
drm/bridge: it6505: Initialize AUX channel in it6505_i2c_probe
During device boot, the HPD interrupt could be triggered before the DRM
subsystem registers it6505 as a DRM bridge. In such cases, the driver
tries to access AUX channel and causes NULL pointer dereference.
Initializing the AUX channel earlier to prevent such error.
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2025123021-CVE-2022-50847-6766@gregkh/T
Wiz
CVE-2022-50847 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
CVE-2022-50847 CVE-2022-50847 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2022-50847 :
Linux Kernel vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
drm/bridge: it6505: Initialize AUX channel in it6505_i2c_probe
During device boot, the HPD interrupt could be triggered before the DRM
subsystem registers it6505 as a DRM bridge. In such cases, the driver
tries to access AUX channel and causes NULL pointer dereference.
Initializing the AUX channel earlier to prevent such error.
Source : NVD
Published December 30, 2025
CNA Score N/A
Affected Technologies
Linux Kernel
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 6.8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
k
2025-12-30
Published