目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2022-50575— Linux kernel 安全漏洞

AI Predicted 3.7 Difficulty: Trivial EPSS 0.21% · P11

Affected Version Matrix 16

ベンダープロダクトVersion Rangeステータス
LinuxLinux3ad0876554cafa368f574d4d408468510543e9ff< 5d68ae32d132ea2af73bc223fd64c46f85302a8baffected
3ad0876554cafa368f574d4d408468510543e9ff< 4f983ee5e5de924d93a7bbb4e6f68f38c6256cd5affected
3ad0876554cafa368f574d4d408468510543e9ff< 46026bb057c35f5bb111bf95e00cd8366d2e34d4affected
3ad0876554cafa368f574d4d408468510543e9ff< 0bf874183b32eae2cc20e3c5be38ec3d33e7e564affected
3ad0876554cafa368f574d4d408468510543e9ff< e0c5f1058ed96f2b7487560c4c4cbd768d13d065affected
3ad0876554cafa368f574d4d408468510543e9ff< 4da411086f5ab32f811a89ef804980ec106ebb65affected
3ad0876554cafa368f574d4d408468510543e9ff< 8b997b2bb2c53b76a6db6c195930e9ab8e4b0c79affected
4.18affected
… +8 more rows
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2022-50575の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
xen/privcmd: Fix a possible warning in privcmd_ioctl_mmap_resource()
ソース: CVE Program / CVE List V5
脆弱性説明
In the Linux kernel, the following vulnerability has been resolved: xen/privcmd: Fix a possible warning in privcmd_ioctl_mmap_resource() As 'kdata.num' is user-controlled data, if user tries to allocate memory larger than(>=) MAX_ORDER, then kcalloc() will fail, it creates a stack trace and messes up dmesg with a warning. Call trace: -> privcmd_ioctl --> privcmd_ioctl_mmap_resource Add __GFP_NOWARN in order to avoid too large allocation warning. This is detected by static analysis using smatch.
ソース: CVE Program / CVE List V5
CVSS情報
N/A
ソース: CVE Program / CVE List V5
脆弱性タイプ
N/A
ソース: CVE Program / CVE List V5
脆弱性タイトル
Linux kernel 安全漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于未限制用户控制的内存分配大小,可能导致拒绝服务攻击。
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
LinuxLinux 3ad0876554cafa368f574d4d408468510543e9ff ~ 5d68ae32d132ea2af73bc223fd64c46f85302a8b -
LinuxLinux 4.18 -

II. CVE-2022-50575の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2022-50575のインテリジェンス情報

登录查看更多情报信息。

CVE-2022-50575 补丁与修复 (7)

Same Patch Batch · Linux · 2025-10-22 · 67 CVEs total

CVE-2023-537118.2 HIGHNFS: Fix a potential data corruption
CVE-2023-537058.2 HIGHipv6: Fix out-of-bounds access in ipv6_find_tlv()
CVE-2023-536987.8 HIGHxsk: fix refcount underflow in error path
CVE-2023-536927.8 HIGHext4: fix use-after-free read in ext4_find_extent for bigalloc + inline
CVE-2022-505697.8 HIGHxfrm: Update ipcomp_scratches with NULL when freed
CVE-2022-505707.8 HIGHplatform/chrome: fix memory corruption in ioctl
CVE-2022-505677.8 HIGHfs: jfs: fix shift-out-of-bounds in dbAllocAG
CVE-2023-537187.8 HIGHring-buffer: Do not swap cpu_buffer during resize process
CVE-2023-536957.8 HIGHudf: Detect system inodes linked into directory hierarchy
CVE-2023-537077.8 HIGHdrm/amdgpu: Fix integer overflow in amdgpu_cs_pass1
CVE-2022-505817.8 HIGHhfs: fix OOB Read in __hfs_brec_find
CVE-2023-537297.8 HIGHsoc: qcom: qmi_encdec: Restrict string length in decode
CVE-2023-537137.8 HIGHarm64: sme: Use STR P to clear FFR context field in streaming SVE mode
CVE-2023-537267.1 HIGHarm64: csum: Fix OoB access in IP checksum code for negative lengths
CVE-2023-53704clk: imx: clk-imx8mp: improve error handling in imx8mp_clocks_probe()
CVE-2023-53706mm/vmemmap/devdax: fix kernel crash when probing devdax devices
CVE-2023-53710wifi: mt76: mt7921: fix error code of return in mt7921_acpi_read
CVE-2023-53708ACPI: x86: s2idle: Catch multiple ACPI_TYPE_PACKAGE objects
CVE-2023-53712ARM: 9317/1: kexec: Make smp stop calls asynchronous
CVE-2023-53714drm/stm: ltdc: fix late dereference check

Showing 20 of 67 CVEs. View all on vendor page →

IV. 関連脆弱性

V. CVE-2022-50575へのコメント

まだコメントはありません


コメントを残す