CVE-2022-50833
Last modified
CVE-2022-50833 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: Bluetooth: use hdev->workqueue when queuing hdev->{cmd,ncmd}_timer works syzbot is reporting attempt to schedule hdev->cmd_work work from system_wq WQ into hdev->workqueue WQ which is under draining operation [1], for commit c8efcc2589464ac7 ("workqueue: allow chained queueing during destruction") does not allow such operation. The check introduced by commit 877afadad2dce8aa ("Bluetooth: When HCI work queue is drained, only queue chained work") was incomplete. Use hdev->workqueue WQ when queuing hdev->{cmd,ncmd}_timer works because hci_{cmd,ncmd}_timeout() calls queue_work(hdev->workqueue). Also, protect the queuing operation with RCU read lock in order to avoid calling queue_delayed_work() after cancel_delayed_work() completed.. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: use hdev->workqueue when queuing hdev->{cmd,ncmd}_timer works syzbot is reporting attempt to schedule hdev->cmd_work work from system_wq WQ into hdev->workqueue WQ which is under draining operation [1], for commit c8efcc2589464ac7 ("workqueue: allow chained queueing during destruction") does not allow such operation. The check introduced by commit 877afadad2dce8aa ("Bluetooth: When HCI work queue is drained, only queue chained work") was incomplete. Use hdev->workqueue WQ when queuing hdev->{cmd,ncmd}_timer works because hci_{cmd,ncmd}_timeout() calls queue_work(hdev->workqueue). Also, protect the queuing operation with RCU read lock in order to avoid calling queue_delayed_work() after cancel_delayed_work() completed.
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 3b382555706558f5c0587862b6dc03e96a252bba, < c4635cf3d845a7324c25c52d549b70c8bd7ad4c7; >= 877afadad2dce8aae1f2aad8ce47e072d4f6165e, < 3c6b036fe5c8ed8b6c4cbdc03605929882907ef0; >= 877afadad2dce8aae1f2aad8ce47e072d4f6165e, < deee93d13d385103205879a8a0915036ecd83261; 4bf367fa1fefabdf14938d0ac9ed60020389112e; >= 5.19.2, < 5.19.15; >= 5.18.18, < 5.19 |
| Linux | Linux | 6.0 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2022-50833?
How severe is CVE-2022-50833?
How do I fix CVE-2022-50833?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-50827In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50828In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50829In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50830In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50831Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2022-50832In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50834In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50835In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50836In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50837In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50838In the Linux kernel, the following vulnerability has been re…
- CVE-2022-50839In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2022-50833?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
