CVE-2022-50786

UnknownEPSS 0.17%

Last modified

CVE-2022-50786 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: media: s5p-mfc: Clear workbit to handle error condition During error on CLOSE_INSTANCE command, ctx_work_bits was not getting cleared. During consequent mfc execution NULL pointer dereferencing of this context led to kernel panic. EPSS estimates a 0.17% chance of exploitation in the next 30 days.

Description

In the Linux kernel, the following vulnerability has been resolved: media: s5p-mfc: Clear workbit to handle error condition During error on CLOSE_INSTANCE command, ctx_work_bits was not getting cleared. During consequent mfc execution NULL pointer dereferencing of this context led to kernel panic. This patch fixes this issue by making sure to clear ctx_work_bits always.

Metrics

EPSS Probability
0.17%

7.0th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= 818cd91ab8c6e42c2658c8e61f8462637c6f586b, < 12242bd13ce68acd571b2cce6ab302e154e8a4ee; >= 818cd91ab8c6e42c2658c8e61f8462637c6f586b, < 640075400c7c577b0f5369b935e22a588773fafa; >= 818cd91ab8c6e42c2658c8e61f8462637c6f586b, < 8ff64edf9d16e8c277dcc8189794763624e6b4b8; >= 818cd91ab8c6e42c2658c8e61f8462637c6f586b, < ff27800c0a6d81571671b33f696109804d015409; >= 818cd91ab8c6e42c2658c8e61f8462637c6f586b, < 09c1fbbe532758e4046c20829f4c0c50b99332dc; >= 818cd91ab8c6e42c2658c8e61f8462637c6f586b, < bd1b72f0c39a0d791a087b4e643701a48328ba8e; >= 818cd91ab8c6e42c2658c8e61f8462637c6f586b, < d3f3c2fe54e30b0636496d842ffbb5ad3a547f9b
LinuxLinux3.16

References

Timeline

Published
Last Modified
Status
Deferred

Frequently Asked Questions

What is CVE-2022-50786?
In the Linux kernel, the following vulnerability has been resolved: media: s5p-mfc: Clear workbit to handle error condition During error on CLOSE_INSTANCE command, ctx_work_bits was not getting cleared. During consequent mfc execution NULL pointer dereferencing of this context led to kernel panic. This patch fixes this issue by making sure to clear ctx_work_bits always.
How severe is CVE-2022-50786?
Severity scoring for CVE-2022-50786 is pending analysis. The EPSS model estimates a 0.17% probability of exploitation in the next 30 days.
How do I fix CVE-2022-50786?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2022

Are you affected by CVE-2022-50786?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST