Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2022-50819— udmabuf: Set ubuf->sg = NULL if the creation of sg table fails

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于sg表创建失败时未将ubuf->sg设置为NULL,可能导致空指针取消引用。

AI Predicted 5.5 Difficulty: Moderate EPSS 0.21% · P12

Possible ATT&CK Techniques 1 AI

T1211 · Exploitation for Stealth

Affected Version Matrix 12

VendorProduct Version RangeStatus
Linux Linux 284562e1f34874e267d4f499362c3816f8f6bc3f< bbe2f6f90310b3a0b5de4e0dc022b36faabfd718 affected
284562e1f34874e267d4f499362c3816f8f6bc3f< dfbed8c92eb853929f4fa676ba493391dab47be4 affected
284562e1f34874e267d4f499362c3816f8f6bc3f< fc285549f454c0f50f87ec945fc0bf44719c0fa4 affected
284562e1f34874e267d4f499362c3816f8f6bc3f< 9861e43f097a50678041f973347b3a88f2da09cf affected
284562e1f34874e267d4f499362c3816f8f6bc3f< d9c04a1b7a15b5e74b2977461d9511e497f05d8f affected
5.6 affected
< 5.6 unaffected
5.10.150≤ 5.10.* unaffected
… +4 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2022-50819

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
udmabuf: Set ubuf->sg = NULL if the creation of sg table fails
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: udmabuf: Set ubuf->sg = NULL if the creation of sg table fails When userspace tries to map the dmabuf and if for some reason (e.g. OOM) the creation of the sg table fails, ubuf->sg needs to be set to NULL. Otherwise, when the userspace subsequently closes the dmabuf fd, we'd try to erroneously free the invalid sg table from release_udmabuf resulting in the following crash reported by syzbot: general protection fault, probably for non-canonical address 0xdffffc0000000000: 0000 [#1] PREEMPT SMP KASAN KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007] CPU: 0 PID: 3609 Comm: syz-executor487 Not tainted 5.19.0-syzkaller-13930-g7ebfc85e2cd7 #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/22/2022 RIP: 0010:dma_unmap_sgtable include/linux/dma-mapping.h:378 [inline] RIP: 0010:put_sg_table drivers/dma-buf/udmabuf.c:89 [inline] RIP: 0010:release_udmabuf+0xcb/0x4f0 drivers/dma-buf/udmabuf.c:114 Code: 48 89 fa 48 c1 ea 03 80 3c 02 00 0f 85 2b 04 00 00 48 8d 7d 0c 4c 8b 63 30 48 b8 00 00 00 00 00 fc ff df 48 89 fa 48 c1 ea 03 <0f> b6 14 02 48 89 f8 83 e0 07 83 c0 03 38 d0 7c 08 84 d2 0f 85 e2 RSP: 0018:ffffc900037efd30 EFLAGS: 00010246 RAX: dffffc0000000000 RBX: ffffffff8cb67800 RCX: 0000000000000000 RDX: 0000000000000000 RSI: ffffffff84ad27e0 RDI: 0000000000000000 RBP: fffffffffffffff4 R08: 0000000000000005 R09: 0000000000000000 R10: 0000000000000000 R11: 000000000008c07c R12: ffff88801fa05000 R13: ffff888073db07e8 R14: ffff888025c25440 R15: 0000000000000000 FS: 0000555555fc4300(0000) GS:ffff8880b9a00000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007fc1c0ce06e4 CR3: 00000000715e6000 CR4: 00000000003506f0 DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 Call Trace: <TASK> dma_buf_release+0x157/0x2d0 drivers/dma-buf/dma-buf.c:78 __dentry_kill+0x42b/0x640 fs/dcache.c:612 dentry_kill fs/dcache.c:733 [inline] dput+0x806/0xdb0 fs/dcache.c:913 __fput+0x39c/0x9d0 fs/file_table.c:333 task_work_run+0xdd/0x1a0 kernel/task_work.c:177 ptrace_notify+0x114/0x140 kernel/signal.c:2353 ptrace_report_syscall include/linux/ptrace.h:420 [inline] ptrace_report_syscall_exit include/linux/ptrace.h:482 [inline] syscall_exit_work kernel/entry/common.c:249 [inline] syscall_exit_to_user_mode_prepare+0x129/0x280 kernel/entry/common.c:276 __syscall_exit_to_user_mode_work kernel/entry/common.c:281 [inline] syscall_exit_to_user_mode+0x9/0x50 kernel/entry/common.c:294 do_syscall_64+0x42/0xb0 arch/x86/entry/common.c:86 entry_SYSCALL_64_after_hwframe+0x63/0xcd RIP: 0033:0x7fc1c0c35b6b Code: 0f 05 48 3d 00 f0 ff ff 77 45 c3 0f 1f 40 00 48 83 ec 18 89 7c 24 0c e8 63 fc ff ff 8b 7c 24 0c 41 89 c0 b8 03 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 35 44 89 c7 89 44 24 0c e8 a1 fc ff ff 8b 44 RSP: 002b:00007ffd78a06090 EFLAGS: 00000293 ORIG_RAX: 0000000000000003 RAX: 0000000000000000 RBX: 0000000000000007 RCX: 00007fc1c0c35b6b RDX: 0000000020000280 RSI: 0000000040086200 RDI: 0000000000000006 RBP: 0000000000000007 R08: 0000000000000000 R09: 0000000000000000 R10: 0000000000000000 R11: 0000000000000293 R12: 000000000000000c R13: 0000000000000003 R14: 00007fc1c0cfe4a0 R15: 00007ffd78a06140 </TASK> Modules linked in: ---[ end trace 0000000000000000 ]--- RIP: 0010:dma_unmap_sgtable include/linux/dma-mapping.h:378 [inline] RIP: 0010:put_sg_table drivers/dma-buf/udmabuf.c:89 [inline] RIP: 0010:release_udmabuf+0xcb/0x4f0 drivers/dma-buf/udmabuf.c:114
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于sg表创建失败时未将ubuf->sg设置为NULL,可能导致空指针取消引用。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 284562e1f34874e267d4f499362c3816f8f6bc3f ~ bbe2f6f90310b3a0b5de4e0dc022b36faabfd718 -
Linux Linux 5.6 -

II. Public POCs for CVE-2022-50819

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2022-50819

登录查看更多情报信息。

Other References for CVE-2022-50819 (5)

Same Patch Batch · Linux · 2025-12-30 · 244 CVEs total

CVE-2023-54184 9.8 CRITICAL scsi: target: iscsit: Free cmds before session free
CVE-2023-54223 9.8 CRITICAL net/mlx5e: xsk: Fix invalid buffer access for legacy rq
CVE-2023-54237 9.8 CRITICAL net/smc: fix potential panic dues to unprotected smc_llc_srv_add_link()
CVE-2023-54292 9.8 CRITICAL RDMA/irdma: Fix data race on CQP request done
CVE-2023-54280 9.8 CRITICAL cifs: fix potential race when tree connecting ipc
CVE-2023-54269 9.8 CRITICAL SUNRPC: double free xprt_ctxt while still in use
CVE-2023-54258 9.8 CRITICAL cifs: fix potential oops in cifs_oplock_break
CVE-2023-54257 9.8 CRITICAL net: macb: fix a memory corruption in extended buffer descriptor mode
CVE-2023-54203 9.1 CRITICAL ksmbd: fix slab-out-of-bounds in init_smb2_rsp_hdr
CVE-2023-54318 8.8 HIGH net/smc: use smc_lgr_list.lock to protect smc_lgr_list.list iterate in smcr_port_add
CVE-2023-54162 8.8 HIGH ksmbd: fix possible memory leak in smb2_lock()
CVE-2023-54214 8.8 HIGH Bluetooth: L2CAP: Fix potential user-after-free
CVE-2022-50880 8.8 HIGH wifi: ath10k: add peer map clean up for peer delete in ath10k_sta_state()
CVE-2023-54262 8.8 HIGH net/mlx5e: Don't clone flow post action attributes second time
CVE-2023-54250 8.2 HIGH ksmbd: avoid out of bounds access in decode_preauth_ctxt()
CVE-2023-54164 8.0 HIGH Bluetooth: ISO: fix iso_conn related locking and validity issues
CVE-2023-54202 7.8 HIGH drm/i915: fix race condition UAF in i915_perf_add_config_ioctl
CVE-2023-54317 7.8 HIGH dm flakey: don't corrupt the zero page
CVE-2022-50841 7.8 HIGH fs/ntfs3: Add overflow check for attribute size
CVE-2023-54201 7.8 HIGH RDMA/efa: Fix wrong resources deallocation order

Showing top 20 of 244 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2022-50819

No comments yet


Leave a comment