CVE-2022-50842

UnknownEPSS 0.20%

Last modified

CVE-2022-50842 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: drm/virtio: Check whether transferred 2D BO is shmem Transferred 2D BO always must be a shmem BO. Add check for that to prevent NULL dereference if userspace passes a VRAM BO.. EPSS estimates a 0.20% chance of exploitation in the next 30 days.

Description

In the Linux kernel, the following vulnerability has been resolved: drm/virtio: Check whether transferred 2D BO is shmem Transferred 2D BO always must be a shmem BO. Add check for that to prevent NULL dereference if userspace passes a VRAM BO.

Metrics

EPSS Probability
0.20%

10.1th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= f651c8b055423057d9f41525dfdc37b4796015d1, < f134f261d76ae3d5ecf68db642eaa746ceb84cfb; >= f651c8b055423057d9f41525dfdc37b4796015d1, < f122bcb34f1a4b02ef3d95058d8fd1316ea03785; >= f651c8b055423057d9f41525dfdc37b4796015d1, < 989164305b933af06d69bb91044dafbd01025371; >= f651c8b055423057d9f41525dfdc37b4796015d1, < 36e133af33ea54193378b190cf92c47c12a43d34; >= f651c8b055423057d9f41525dfdc37b4796015d1, < e473216b42aa1fd9fc6b94b608b42c210c655908
LinuxLinux5.7

References

Timeline

Published
Last Modified
Status
Deferred

Frequently Asked Questions

What is CVE-2022-50842?
In the Linux kernel, the following vulnerability has been resolved: drm/virtio: Check whether transferred 2D BO is shmem Transferred 2D BO always must be a shmem BO. Add check for that to prevent NULL dereference if userspace passes a VRAM BO.
How severe is CVE-2022-50842?
Severity scoring for CVE-2022-50842 is pending analysis. The EPSS model estimates a 0.20% probability of exploitation in the next 30 days.
How do I fix CVE-2022-50842?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2022

Are you affected by CVE-2022-50842?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST