Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2022-50674— riscv: vdso: fix NULL deference in vdso_join_timens() when vfork

AI Predicted 6.5 Difficulty: Easy EPSS 0.23% · P14

Possible ATT&CK Techniques 1AI

T1203 · Exploitation for Client Execution

Affected Version Matrix 8

VendorProductVersion RangeStatus
LinuxLinux3092eb45637573c5e435fbf5eaf9516316e5f9c6< df30c4feba51beeb138f3518c2421abc8cbda3c1affected
3092eb45637573c5e435fbf5eaf9516316e5f9c6< f2419a6fbb4caf8cf3fe0ac7e4cf2e28127d04b4affected
3092eb45637573c5e435fbf5eaf9516316e5f9c6< a8616d2dc193b6becc36b5f3cfeaa9ac7a5762f9affected
5.19affected
< 5.19unaffected
5.19.17≤ 5.19.*unaffected
6.0.3≤ 6.0.*unaffected
6.1≤ *unaffected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2022-50674

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
riscv: vdso: fix NULL deference in vdso_join_timens() when vfork
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: riscv: vdso: fix NULL deference in vdso_join_timens() when vfork Testing tools/testing/selftests/timens/vfork_exec.c got below kernel log: [ 6.838454] Unable to handle kernel access to user memory without uaccess routines at virtual address 0000000000000020 [ 6.842255] Oops [#1] [ 6.842871] Modules linked in: [ 6.844249] CPU: 1 PID: 64 Comm: vfork_exec Not tainted 6.0.0-rc3-rt15+ #8 [ 6.845861] Hardware name: riscv-virtio,qemu (DT) [ 6.848009] epc : vdso_join_timens+0xd2/0x110 [ 6.850097] ra : vdso_join_timens+0xd2/0x110 [ 6.851164] epc : ffffffff8000635c ra : ffffffff8000635c sp : ff6000000181fbf0 [ 6.852562] gp : ffffffff80cff648 tp : ff60000000fdb700 t0 : 3030303030303030 [ 6.853852] t1 : 0000000000000030 t2 : 3030303030303030 s0 : ff6000000181fc40 [ 6.854984] s1 : ff60000001e6c000 a0 : 0000000000000010 a1 : ffffffff8005654c [ 6.856221] a2 : 00000000ffffefff a3 : 0000000000000000 a4 : 0000000000000000 [ 6.858114] a5 : 0000000000000000 a6 : 0000000000000008 a7 : 0000000000000038 [ 6.859484] s2 : ff60000001e6c068 s3 : ff6000000108abb0 s4 : 0000000000000000 [ 6.860751] s5 : 0000000000001000 s6 : ffffffff8089dc40 s7 : ffffffff8089dc38 [ 6.862029] s8 : ffffffff8089dc30 s9 : ff60000000fdbe38 s10: 000000000000005e [ 6.863304] s11: ffffffff80cc3510 t3 : ffffffff80d1112f t4 : ffffffff80d1112f [ 6.864565] t5 : ffffffff80d11130 t6 : ff6000000181fa00 [ 6.865561] status: 0000000000000120 badaddr: 0000000000000020 cause: 000000000000000d [ 6.868046] [<ffffffff8008dc94>] timens_commit+0x38/0x11a [ 6.869089] [<ffffffff8008dde8>] timens_on_fork+0x72/0xb4 [ 6.870055] [<ffffffff80190096>] begin_new_exec+0x3c6/0x9f0 [ 6.871231] [<ffffffff801d826c>] load_elf_binary+0x628/0x1214 [ 6.872304] [<ffffffff8018ee7a>] bprm_execve+0x1f2/0x4e4 [ 6.873243] [<ffffffff8018f90c>] do_execveat_common+0x16e/0x1ee [ 6.874258] [<ffffffff8018f9c8>] sys_execve+0x3c/0x48 [ 6.875162] [<ffffffff80003556>] ret_from_syscall+0x0/0x2 [ 6.877484] ---[ end trace 0000000000000000 ]--- This is because the mm->context.vdso_info is NULL in vfork case. From another side, mm->context.vdso_info either points to vdso info for RV64 or vdso info for compat, there's no need to bloat riscv's mm_context_t, we can handle the difference when setup the additional page for vdso.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于vdso_join_timens中未正确处理用户内存访问,可能导致空指针取消引用。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux 3092eb45637573c5e435fbf5eaf9516316e5f9c6 ~ df30c4feba51beeb138f3518c2421abc8cbda3c1 -
LinuxLinux 5.19 -

II. Public POCs for CVE-2022-50674

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2022-50674

登录查看更多情报信息。

Same Patch Batch · Linux · 2025-12-09 · 152 CVEs total

CVE-2025-403439.8 CRITICALnvmet-fc: avoid scheduling association deletion twice
CVE-2023-537949.8 CRITICALcifs: fix session state check in reconnect to avoid use-after-free issue
CVE-2022-506669.8 CRITICALRDMA/siw: Fix QP destroy to wait for all references dropped.
CVE-2023-538278.8 HIGHBluetooth: L2CAP: Fix use-after-free in l2cap_disconnect_{req,rsp}
CVE-2023-537858.8 HIGHmt76: mt7921: don't assume adequate headroom for SDIO headers
CVE-2023-538228.8 HIGHwifi: ath11k: Ignore frags from uninitialized peer in dp.
CVE-2025-403368.8 HIGHdrm/gpusvm: fix hmm_pfn_to_map_order() usage
CVE-2025-403428.8 HIGHnvme-fc: use lock accessing port_state and rport state
CVE-2025-403288.8 HIGHsmb: client: fix potential UAF in smb2_close_cached_fid()
CVE-2023-538518.4 HIGHdrm/msm/dp: Drop aux devices together with DP controller
CVE-2025-403378.2 HIGHnet: stmmac: Correctly handle Rx checksum offload errors
CVE-2022-506568.1 HIGHnfc: pn533: Clear nfc_target before being used
CVE-2023-538038.1 HIGHscsi: ses: Fix slab-out-of-bounds in ses_enclosure_data_process()
CVE-2023-538047.8 HIGHnilfs2: fix use-after-free bug of nilfs_root in nilfs_evict_inode()
CVE-2023-538197.8 HIGHamdgpu: validate offset_in_bo of drm_amdgpu_gem_va
CVE-2023-538167.8 HIGHdrm/amdkfd: fix potential kgd_mem UAFs
CVE-2023-538007.8 HIGHubi: Fix use-after-free when volume resizing failed
CVE-2023-537907.8 HIGHbpf: Zeroing allocated object from slab in bpf memory allocator
CVE-2023-537957.8 HIGHiommufd: IOMMUFD_DESTROY should not increase the refcount
CVE-2023-538107.8 HIGHblk-mq: release crypto keyslot before reporting I/O complete

Showing top 20 of 152 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2022-50674

No comments yet


Leave a comment