CVE-2022-50877
published 2025-12-30CVE-2022-50877: In the Linux kernel, the following vulnerability has been resolved: net: broadcom: bcm4908_enet: update TX stats after actual transmission Queueing packets…
PriorityP421medium5.3
EPSS
0.17%
6.9th percentile
In the Linux kernel, the following vulnerability has been resolved:
net: broadcom: bcm4908_enet: update TX stats after actual transmission
Queueing packets doesn't guarantee their transmission. Update TX stats
after hardware confirms consuming submitted data.
This also fixes a possible race and NULL dereference.
bcm4908_enet_start_xmit() could try to access skb after freeing it in
the bcm4908_enet_poll_tx().
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.0.7-1 (bookworm) | linux 6.0.7-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 4feffeadbcb2e5b11cbbf191a33c245b74a5837b < c9589e18a60c55c76772a38117ef9a16b942e56b | c9589e18a60c55c76772a38117ef9a16b942e56b |
| linux | linux | >= 4feffeadbcb2e5b11cbbf191a33c245b74a5837b < 2adedc80faec243ede55355e57142110d6f46e08 | 2adedc80faec243ede55355e57142110d6f46e08 |
| linux | linux | >= 4feffeadbcb2e5b11cbbf191a33c245b74a5837b < ef3556ee16c68735ec69bd08df41d1cd83b14ad3 | ef3556ee16c68735ec69bd08df41d1cd83b14ad3 |
| linux | linux_kernel | >= 0 < 6.0.7-1 | 6.0.7-1 |
| linux | linux_kernel | >= 0 < 6.0.7-1 | 6.0.7-1 |
| linux | linux_kernel | >= 0 < 6.0.7-1 | 6.0.7-1 |
| linux | linux_kernel | >= 5.12.0 < 5.15.77 | 5.15.77 |
| linux | linux_kernel | >= 5.16.0 < 6.0.7 | 6.0.7 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pqjx-v84v-r7r4: In the Linux kernel, the following vulnerability has been resolved:
net: broadcom: bcm4908_enet: update TX stats after actual transmission
Queueing
ghsa_unreviewed·2025-12-30
CVE-2022-50877 GHSA-pqjx-v84v-r7r4: In the Linux kernel, the following vulnerability has been resolved:
net: broadcom: bcm4908_enet: update TX stats after actual transmission
Queueing
In the Linux kernel, the following vulnerability has been resolved:
net: broadcom: bcm4908_enet: update TX stats after actual transmission
Queueing packets doesn't guarantee their transmission. Update TX stats
after hardware confirms consuming submitted data.
This also fixes a possible race and NULL dereference.
bcm4908_enet_start_xmit() could try to access skb after freeing it in
the bcm4908_enet_poll_tx().
OSV
CVE-2022-50877: In the Linux kernel, the following vulnerability has been resolved: net: broadcom: bcm4908_enet: update TX stats after actual transmission Queueing pa
osv·2025-12-30
CVE-2022-50877 CVE-2022-50877: In the Linux kernel, the following vulnerability has been resolved: net: broadcom: bcm4908_enet: update TX stats after actual transmission Queueing pa
In the Linux kernel, the following vulnerability has been resolved: net: broadcom: bcm4908_enet: update TX stats after actual transmission Queueing packets doesn't guarantee their transmission. Update TX stats after hardware confirms consuming submitted data. This also fixes a possible race and NULL dereference. bcm4908_enet_start_xmit() could try to access skb after freeing it in the bcm4908_enet_poll_tx().
OSV
net: broadcom: bcm4908_enet: update TX stats after actual transmission
osv·2025-12-30
CVE-2022-50877 net: broadcom: bcm4908_enet: update TX stats after actual transmission
net: broadcom: bcm4908_enet: update TX stats after actual transmission
In the Linux kernel, the following vulnerability has been resolved:
net: broadcom: bcm4908_enet: update TX stats after actual transmission
Queueing packets doesn't guarantee their transmission. Update TX stats
after hardware confirms consuming submitted data.
This also fixes a possible race and NULL dereference.
bcm4908_enet_start_xmit() could try to access skb after freeing it in
the bcm4908_enet_poll_tx().
Red Hat
kernel: net: broadcom: bcm4908_enet: update TX stats after actual transmission
vendor_redhat·2025-12-30
CVE-2022-50877 kernel: net: broadcom: bcm4908_enet: update TX stats after actual transmission
kernel: net: broadcom: bcm4908_enet: update TX stats after actual transmission
In the Linux kernel, the following vulnerability has been resolved:
net: broadcom: bcm4908_enet: update TX stats after actual transmission
Queueing packets doesn't guarantee their transmission. Update TX stats
after hardware confirms consuming submitted data.
This also fixes a possible race and NULL dereference.
bcm4908_enet_start_xmit() could try to access skb after freeing it in
the bcm4908_enet_poll_tx().
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Debian
CVE-2022-50877: linux - In the Linux kernel, the following vulnerability has been resolved: net: broadc...
vendor_debian·2022
CVE-2022-50877 CVE-2022-50877: linux - In the Linux kernel, the following vulnerability has been resolved: net: broadc...
In the Linux kernel, the following vulnerability has been resolved: net: broadcom: bcm4908_enet: update TX stats after actual transmission Queueing packets doesn't guarantee their transmission. Update TX stats after hardware confirms consuming submitted data. This also fixes a possible race and NULL dereference. bcm4908_enet_start_xmit() could try to access skb after freeing it in the bcm4908_enet_poll_tx().
Scope: local
bookworm: resolved (fixed in 6.0.7-1)
bullseye: resolved
forky: resolved (fixed in 6.0.7-1)
sid: resolved (fixed in 6.0.7-1)
trixie: resolved (fixed in 6.0.7-1)
No detection rules found.
No public exploits indexed.
Wiz
CVE-2022-50877 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2022-50877 [MEDIUM] CVE-2022-50877 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2022-50877 :
Linux Debian vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
net: broadcom: bcm4908_enet: update TX stats after actual transmission
Queueing packets doesn't guarantee their transmission. Update TX stats
after hardware confirms consuming submitted data.
This also fixes a possible race and NULL dereference.
bcm4908_enet_start_xmit() could try to access skb after freeing it in
the bcm4908_enet_poll_tx().
Source : NVD
Published December 30, 2025
CNA Score N/A
Affected Technologies
Linux Debian
Linux Ubuntu
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 6.8
Exploitation Probability (EPSS) N/A
Affected packages a
Bugzilla
CVE-2022-50877 kernel: net: broadcom: bcm4908_enet: update TX stats after actual transmission
bugzilla·2025-12-30
CVE-2022-50877 CVE-2022-50877 kernel: net: broadcom: bcm4908_enet: update TX stats after actual transmission
CVE-2022-50877 kernel: net: broadcom: bcm4908_enet: update TX stats after actual transmission
In the Linux kernel, the following vulnerability has been resolved:
net: broadcom: bcm4908_enet: update TX stats after actual transmission
Queueing packets doesn't guarantee their transmission. Update TX stats
after hardware confirms consuming submitted data.
This also fixes a possible race and NULL dereference.
bcm4908_enet_start_xmit() could try to access skb after freeing it in
the bcm4908_enet_poll_tx().
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2025123023-CVE-2022-50877-6a05@gregkh/T
2025-12-30
Published