CVE-2022-50712
Last modified
CVE-2022-50712 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: devlink: hold region lock when flushing snapshots Netdevsim triggers a splat on reload, when it destroys regions with snapshots pending: WARNING: CPU: 1 PID: 787 at net/core/devlink.c:6291 devlink_region_snapshot_del+0x12e/0x140 CPU: 1 PID: 787 Comm: devlink Not tainted 6.1.0-07460-g7ae9888d6e1c #580 RIP: 0010:devlink_region_snapshot_del+0x12e/0x140 Call Trace: <TASK> devl_region_destroy+0x70/0x140 nsim_dev_reload_down+0x2f/0x60 [netdevsim] devlink_reload+0x1f7/0x360 devlink_nl_cmd_reload+0x6ce/0x860 genl_family_rcv_msg_doit.isra.0+0x145/0x1c0 This is the locking assert in devlink_region_snapshot_del(), we're supposed to be holding the region->snapshot_lock here.. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: devlink: hold region lock when flushing snapshots Netdevsim triggers a splat on reload, when it destroys regions with snapshots pending: WARNING: CPU: 1 PID: 787 at net/core/devlink.c:6291 devlink_region_snapshot_del+0x12e/0x140 CPU: 1 PID: 787 Comm: devlink Not tainted 6.1.0-07460-g7ae9888d6e1c #580 RIP: 0010:devlink_region_snapshot_del+0x12e/0x140 Call Trace: <TASK> devl_region_destroy+0x70/0x140 nsim_dev_reload_down+0x2f/0x60 [netdevsim] devlink_reload+0x1f7/0x360 devlink_nl_cmd_reload+0x6ce/0x860 genl_family_rcv_msg_doit.isra.0+0x145/0x1c0 This is the locking assert in devlink_region_snapshot_del(), we're supposed to be holding the region->snapshot_lock here.
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 2dec18ad826f52658f7781ee995d236cc449b678, < 49383d4e59bb704341aaa1d51440ccce58270e61; >= 2dec18ad826f52658f7781ee995d236cc449b678, < 6298cab4d80bfdb6fe01fe31fd9f0ba26317fdae; >= 2dec18ad826f52658f7781ee995d236cc449b678, < b4cafb3d2c740f8d1b1234b43ac4a60e5291c960 |
| Linux | Linux | 6.0 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2022-50712?
How severe is CVE-2022-50712?
How do I fix CVE-2022-50712?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-50706In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50707In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50708In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50709In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50710In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50711In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50713In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50714In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50715In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50716In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50717In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2022-50718In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2022-50712?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
