CVE-2022-50884
published 2025-12-30CVE-2022-50884: In the Linux kernel, the following vulnerability has been resolved: drm: Prevent drm_copy_field() to attempt copying a NULL pointer There are some struct…
PriorityP423low5.5
EPSS
0.20%
10.5th percentile
In the Linux kernel, the following vulnerability has been resolved:
drm: Prevent drm_copy_field() to attempt copying a NULL pointer
There are some struct drm_driver fields that are required by drivers since
drm_copy_field() attempts to copy them to user-space via DRM_IOCTL_VERSION.
But it can be possible that a driver has a bug and did not set some of the
fields, which leads to drm_copy_field() attempting to copy a NULL pointer:
[ +10.395966] Unable to handle kernel access to user memory outside uaccess routines at virtual address 0000000000000000
[ +0.010955] Mem abort info:
[ +0.002835] ESR = 0x0000000096000004
[ +0.003872] EC = 0x25: DABT (current EL), IL = 32 bits
[ +0.005395] SET = 0, FnV = 0
[ +0.003113] EA = 0, S1PTW = 0
[ +0.003182] FSC = 0x04: level 0 translation fault
[ +0.004964] Data abort info:
[ +0.002919] ISV = 0, ISS = 0x00000004
[ +0.003886] CM = 0, WnR = 0
[ +0.003040] user pgtable: 4k pages, 48-bit VAs, pgdp=0000000115dad000
[ +0.006536] [0000000000000000] pgd=0000000000000000, p4d=0000000000000000
[ +0.006925] Internal error: Oops: 96000004 [#1] SMP
...
[ +0.011113] pstate: 80400005 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
[ +0.007061] pc : __pi_strlen+0x14/0x150
[ +0.003895] lr : drm_copy_field+0x30/0x1a4
[ +0.004156] sp : ffff8000094b3a50
[ +0.003355] x29: ffff8000094b3a50 x28: ffff8000094b3b70 x27: 0000000000000040
[ +0.007242] x26: ffff443743c2ba00 x25: 0000000000000000 x24: 0000000000000040
[ +0.007243] x23: ffff443743c2ba00 x22: ffff8000094b3b70 x21: 0000000000000000
[ +0.007241] x20: 0000000000000000 x19: ffff8000094b3b90 x18: 0000000000000000
[ +0.007241] x17: 0000000000000000 x16: 0000000000000000 x15: 0000aaab14b9af40
[ +0.007241] x14: 0000000000000000 x13: 0000000000000000 x12: 0000000000000000
[ +0.007239] x11: 0000000000000000 x10: 0000000000000000 x9 : ffffa524ad67d4d8
[ +0.007242] x8 : 0101010101010101 x7 : 7f7f7f7f7f7f7f7f x6 : 6c6e6263606e7141
[ +0.007239] x5 : 0000000000000000 x4 : 0000000000000000 x3 : 000000000000000
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.0.3-1 (bookworm) | linux 6.0.3-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 22eae947bf76e236ba972f2f11cfd1b083b736ad < d213914386a0ede76a4549b41de30192fb92c595 | d213914386a0ede76a4549b41de30192fb92c595 |
| linux | linux | >= 22eae947bf76e236ba972f2f11cfd1b083b736ad < ee9885cd936aad88f84d0cf90bf9a70e83e42a97 | ee9885cd936aad88f84d0cf90bf9a70e83e42a97 |
| linux | linux | >= 22eae947bf76e236ba972f2f11cfd1b083b736ad < 8052612b9d08048ebbebcb572894670b4ac07d2f | 8052612b9d08048ebbebcb572894670b4ac07d2f |
| linux | linux | >= 22eae947bf76e236ba972f2f11cfd1b083b736ad < cdde55f97298e5bb9af6d41c9303a3ec545a370e | cdde55f97298e5bb9af6d41c9303a3ec545a370e |
| linux | linux | >= 22eae947bf76e236ba972f2f11cfd1b083b736ad < c28a8082b25ce4ec94999e10a30c50d20bd44a25 | c28a8082b25ce4ec94999e10a30c50d20bd44a25 |
| linux | linux | >= 22eae947bf76e236ba972f2f11cfd1b083b736ad < ca163e389f0ae096a4e1e19f0a95e60ed80b4e31 | ca163e389f0ae096a4e1e19f0a95e60ed80b4e31 |
| linux | linux | >= 22eae947bf76e236ba972f2f11cfd1b083b736ad < 2d6708ea5c2033ff53267feff1876a717689989f | 2d6708ea5c2033ff53267feff1876a717689989f |
| linux | linux | >= 22eae947bf76e236ba972f2f11cfd1b083b736ad < 6cf5e9356b2d856403ee480f987f3ea64dbf8d8c | 6cf5e9356b2d856403ee480f987f3ea64dbf8d8c |
| linux | linux | >= 22eae947bf76e236ba972f2f11cfd1b083b736ad < f6ee30407e883042482ad4ad30da5eaba47872ee | f6ee30407e883042482ad4ad30da5eaba47872ee |
| linux | linux_kernel | >= 0 < 5.10.158-1 | 5.10.158-1 |
| linux | linux_kernel | >= 0 < 6.0.3-1 | 6.0.3-1 |
| linux | linux_kernel | >= 0 < 6.0.3-1 | 6.0.3-1 |
| linux | linux_kernel | >= 0 < 6.0.3-1 | 6.0.3-1 |
| linux | linux_kernel | >= 2.6.16 < 4.9.331 | 4.9.331 |
| linux | linux_kernel | >= 4.10.0 < 4.14.296 | 4.14.296 |
| linux | linux_kernel | >= 4.15.0 < 4.19.262 | 4.19.262 |
| linux | linux_kernel | >= 4.20.0 < 5.4.220 | 5.4.220 |
| linux | linux_kernel | >= 5.11.0 < 5.15.75 | 5.15.75 |
| linux | linux_kernel | >= 5.16.0 < 5.19.17 | 5.19.17 |
| linux | linux_kernel | >= 5.20.0 < 6.0.3 | 6.0.3 |
| linux | linux_kernel | >= 5.5.0 < 5.10.150 | 5.10.150 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8j2h-xvv4-99jg: In the Linux kernel, the following vulnerability has been resolved:
drm: Prevent drm_copy_field() to attempt copying a NULL pointer
There are some s
ghsa_unreviewed·2025-12-30
CVE-2022-50884 GHSA-8j2h-xvv4-99jg: In the Linux kernel, the following vulnerability has been resolved:
drm: Prevent drm_copy_field() to attempt copying a NULL pointer
There are some s
In the Linux kernel, the following vulnerability has been resolved:
drm: Prevent drm_copy_field() to attempt copying a NULL pointer
There are some struct drm_driver fields that are required by drivers since
drm_copy_field() attempts to copy them to user-space via DRM_IOCTL_VERSION.
But it can be possible that a driver has a bug and did not set some of the
fields, which leads to drm_copy_field() attempting to copy a NULL pointer:
[ +10.395966] Unable to handle kernel access to user memory outside uaccess routines at virtual address 0000000000000000
[ +0.010955] Mem abort info:
[ +0.002835] ESR = 0x0000000096000004
[ +0.003872] EC = 0x25: DABT (current EL), IL = 32 bits
[ +0.005395] SET = 0, FnV = 0
[ +0.003113] EA = 0, S1PTW = 0
[ +0.003182] FSC = 0x04: level 0 translation fault
[ +0.00
OSV
drm: Prevent drm_copy_field() to attempt copying a NULL pointer
osv·2025-12-30
CVE-2022-50884 drm: Prevent drm_copy_field() to attempt copying a NULL pointer
drm: Prevent drm_copy_field() to attempt copying a NULL pointer
In the Linux kernel, the following vulnerability has been resolved:
drm: Prevent drm_copy_field() to attempt copying a NULL pointer
There are some struct drm_driver fields that are required by drivers since
drm_copy_field() attempts to copy them to user-space via DRM_IOCTL_VERSION.
But it can be possible that a driver has a bug and did not set some of the
fields, which leads to drm_copy_field() attempting to copy a NULL pointer:
[ +10.395966] Unable to handle kernel access to user memory outside uaccess routines at virtual address 0000000000000000
[ +0.010955] Mem abort info:
[ +0.002835] ESR = 0x0000000096000004
[ +0.003872] EC = 0x25: DABT (current EL), IL = 32 bits
[ +0.005395] SET = 0, FnV = 0
[ +0.003113] EA = 0, S1P
OSV
CVE-2022-50884: In the Linux kernel, the following vulnerability has been resolved: drm: Prevent drm_copy_field() to attempt copying a NULL pointer There are some str
osv·2025-12-30
CVE-2022-50884 CVE-2022-50884: In the Linux kernel, the following vulnerability has been resolved: drm: Prevent drm_copy_field() to attempt copying a NULL pointer There are some str
In the Linux kernel, the following vulnerability has been resolved: drm: Prevent drm_copy_field() to attempt copying a NULL pointer There are some struct drm_driver fields that are required by drivers since drm_copy_field() attempts to copy them to user-space via DRM_IOCTL_VERSION. But it can be possible that a driver has a bug and did not set some of the fields, which leads to drm_copy_field() attempting to copy a NULL pointer: [ +10.395966] Unable to handle kernel access to user memory outside uaccess routines at virtual address 0000000000000000 [ +0.010955] Mem abort info: [ +0.002835] ESR = 0x0000000096000004 [ +0.003872] EC = 0x25: DABT (current EL), IL = 32 bits [ +0.005395] SET = 0, FnV = 0 [ +0.003113] EA = 0, S1PTW = 0 [ +0.003182] FSC = 0x04: level 0 translation fault [ +0.004964
Red Hat
kernel: drm: Prevent drm_copy_field() to attempt copying a NULL pointer
vendor_redhat·2025-12-30·CVSS 5.5
CVE-2022-50884 [LOW] CWE-476 kernel: drm: Prevent drm_copy_field() to attempt copying a NULL pointer
kernel: drm: Prevent drm_copy_field() to attempt copying a NULL pointer
In the Linux kernel, the following vulnerability has been resolved:
drm: Prevent drm_copy_field() to attempt copying a NULL pointer
There are some struct drm_driver fields that are required by drivers since
drm_copy_field() attempts to copy them to user-space via DRM_IOCTL_VERSION.
But it can be possible that a driver has a bug and did not set some of the
fields, which leads to drm_copy_field() attempting to copy a NULL pointer:
[ +10.395966] Unable to handle kernel access to user memory outside uaccess routines at virtual address 0000000000000000
[ +0.010955] Mem abort info:
[ +0.002835] ESR = 0x0000000096000004
[ +0.003872] EC = 0x25: DABT (current EL), IL = 32 bits
[ +0.005395] SET = 0, FnV = 0
[ +0.003113] EA = 0,
Debian
CVE-2022-50884: linux - In the Linux kernel, the following vulnerability has been resolved: drm: Preven...
vendor_debian·2022
CVE-2022-50884 CVE-2022-50884: linux - In the Linux kernel, the following vulnerability has been resolved: drm: Preven...
In the Linux kernel, the following vulnerability has been resolved: drm: Prevent drm_copy_field() to attempt copying a NULL pointer There are some struct drm_driver fields that are required by drivers since drm_copy_field() attempts to copy them to user-space via DRM_IOCTL_VERSION. But it can be possible that a driver has a bug and did not set some of the fields, which leads to drm_copy_field() attempting to copy a NULL pointer: [ +10.395966] Unable to handle kernel access to user memory outside uaccess routines at virtual address 0000000000000000 [ +0.010955] Mem abort info: [ +0.002835] ESR = 0x0000000096000004 [ +0.003872] EC = 0x25: DABT (current EL), IL = 32 bits [ +0.005395] SET = 0, FnV = 0 [ +0.003113] EA = 0, S1PTW = 0 [ +0.003182] FSC = 0x04: level 0 translation fault [ +0.004964
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2022-50884 kernel: drm: Prevent drm_copy_field() to attempt copying a NULL pointer
bugzilla·2025-12-30
CVE-2022-50884 [LOW] CVE-2022-50884 kernel: drm: Prevent drm_copy_field() to attempt copying a NULL pointer
CVE-2022-50884 kernel: drm: Prevent drm_copy_field() to attempt copying a NULL pointer
In the Linux kernel, the following vulnerability has been resolved:
drm: Prevent drm_copy_field() to attempt copying a NULL pointer
There are some struct drm_driver fields that are required by drivers since
drm_copy_field() attempts to copy them to user-space via DRM_IOCTL_VERSION.
But it can be possible that a driver has a bug and did not set some of the
fields, which leads to drm_copy_field() attempting to copy a NULL pointer:
[ +10.395966] Unable to handle kernel access to user memory outside uaccess routines at virtual address 0000000000000000
[ +0.010955] Mem abort info:
[ +0.002835] ESR = 0x0000000096000004
[ +0.003872] EC = 0x25: DABT (current EL), IL = 32 bits
[ +0.005395] SET = 0, FnV = 0
[
Wiz
CVE-2022-50884 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
CVE-2022-50884 CVE-2022-50884 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2022-50884 :
Linux Kernel vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
drm: Prevent drm_copy_field() to attempt copying a NULL pointer
There are some struct drm_driver fields that are required by drivers since
drm_copy_field() attempts to copy them to user-space via DRM_IOCTL_VERSION.
But it can be possible that a driver has a bug and did not set some of the
fields, which leads to drm_copy_field() attempting to copy a NULL pointer:
[ +10.395966] Unable to handle kernel access to user memory outside uaccess routines at virtual address 0000000000000000
[ +0.010955] Mem abort info:
[ +0.002835] ESR = 0x0000000096000004
[ +0.003872] EC = 0x25: DABT (current EL), IL = 32 bits
[ +0.005395] SET = 0, FnV = 0
[ +0.003113] EA
https://git.kernel.org/stable/c/2d6708ea5c2033ff53267feff1876a717689989fhttps://git.kernel.org/stable/c/6cf5e9356b2d856403ee480f987f3ea64dbf8d8chttps://git.kernel.org/stable/c/8052612b9d08048ebbebcb572894670b4ac07d2fhttps://git.kernel.org/stable/c/c28a8082b25ce4ec94999e10a30c50d20bd44a25https://git.kernel.org/stable/c/ca163e389f0ae096a4e1e19f0a95e60ed80b4e31https://git.kernel.org/stable/c/cdde55f97298e5bb9af6d41c9303a3ec545a370ehttps://git.kernel.org/stable/c/d213914386a0ede76a4549b41de30192fb92c595https://git.kernel.org/stable/c/ee9885cd936aad88f84d0cf90bf9a70e83e42a97https://git.kernel.org/stable/c/f6ee30407e883042482ad4ad30da5eaba47872ee
2025-12-30
Published