Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2022-50575— xen/privcmd: Fix a possible warning in privcmd_ioctl_mmap_resource()

AI Predicted 3.7 Difficulty: Trivial EPSS 0.21% · P11

Affected Version Matrix 16

VendorProductVersion RangeStatus
LinuxLinux3ad0876554cafa368f574d4d408468510543e9ff< 5d68ae32d132ea2af73bc223fd64c46f85302a8baffected
3ad0876554cafa368f574d4d408468510543e9ff< 4f983ee5e5de924d93a7bbb4e6f68f38c6256cd5affected
3ad0876554cafa368f574d4d408468510543e9ff< 46026bb057c35f5bb111bf95e00cd8366d2e34d4affected
3ad0876554cafa368f574d4d408468510543e9ff< 0bf874183b32eae2cc20e3c5be38ec3d33e7e564affected
3ad0876554cafa368f574d4d408468510543e9ff< e0c5f1058ed96f2b7487560c4c4cbd768d13d065affected
3ad0876554cafa368f574d4d408468510543e9ff< 4da411086f5ab32f811a89ef804980ec106ebb65affected
3ad0876554cafa368f574d4d408468510543e9ff< 8b997b2bb2c53b76a6db6c195930e9ab8e4b0c79affected
4.18affected
… +8 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2022-50575

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
xen/privcmd: Fix a possible warning in privcmd_ioctl_mmap_resource()
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: xen/privcmd: Fix a possible warning in privcmd_ioctl_mmap_resource() As 'kdata.num' is user-controlled data, if user tries to allocate memory larger than(>=) MAX_ORDER, then kcalloc() will fail, it creates a stack trace and messes up dmesg with a warning. Call trace: -> privcmd_ioctl --> privcmd_ioctl_mmap_resource Add __GFP_NOWARN in order to avoid too large allocation warning. This is detected by static analysis using smatch.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于未限制用户控制的内存分配大小,可能导致拒绝服务攻击。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux 3ad0876554cafa368f574d4d408468510543e9ff ~ 5d68ae32d132ea2af73bc223fd64c46f85302a8b -
LinuxLinux 4.18 -

II. Public POCs for CVE-2022-50575

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2022-50575

登录查看更多情报信息。

Patches & Fixes for CVE-2022-50575 (7)

Same Patch Batch · Linux · 2025-10-22 · 67 CVEs total

CVE-2023-537118.2 HIGHNFS: Fix a potential data corruption
CVE-2023-537058.2 HIGHipv6: Fix out-of-bounds access in ipv6_find_tlv()
CVE-2023-536987.8 HIGHxsk: fix refcount underflow in error path
CVE-2023-536927.8 HIGHext4: fix use-after-free read in ext4_find_extent for bigalloc + inline
CVE-2022-505697.8 HIGHxfrm: Update ipcomp_scratches with NULL when freed
CVE-2022-505707.8 HIGHplatform/chrome: fix memory corruption in ioctl
CVE-2022-505677.8 HIGHfs: jfs: fix shift-out-of-bounds in dbAllocAG
CVE-2023-537187.8 HIGHring-buffer: Do not swap cpu_buffer during resize process
CVE-2023-536957.8 HIGHudf: Detect system inodes linked into directory hierarchy
CVE-2023-537077.8 HIGHdrm/amdgpu: Fix integer overflow in amdgpu_cs_pass1
CVE-2022-505817.8 HIGHhfs: fix OOB Read in __hfs_brec_find
CVE-2023-537297.8 HIGHsoc: qcom: qmi_encdec: Restrict string length in decode
CVE-2023-537137.8 HIGHarm64: sme: Use STR P to clear FFR context field in streaming SVE mode
CVE-2023-537267.1 HIGHarm64: csum: Fix OoB access in IP checksum code for negative lengths
CVE-2023-53704clk: imx: clk-imx8mp: improve error handling in imx8mp_clocks_probe()
CVE-2023-53706mm/vmemmap/devdax: fix kernel crash when probing devdax devices
CVE-2023-53710wifi: mt76: mt7921: fix error code of return in mt7921_acpi_read
CVE-2023-53708ACPI: x86: s2idle: Catch multiple ACPI_TYPE_PACKAGE objects
CVE-2023-53712ARM: 9317/1: kexec: Make smp stop calls asynchronous
CVE-2023-53714drm/stm: ltdc: fix late dereference check

Showing top 20 of 67 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2022-50575

No comments yet


Leave a comment