Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2022-50440— drm/vmwgfx: Validate the box size for the snooped cursor

AI Predicted 5.3 Difficulty: Easy EPSS 0.15% · P5

Possible ATT&CK Techniques 1AI

T1203 · Exploitation for Client Execution

Affected Version Matrix 20

VendorProductVersion RangeStatus
LinuxLinux2ac863719e518ae1a8f328849e64ea26a222f079< ee8d31836cbe7c26e207bfa0a4a726f0a25cfcf6affected
2ac863719e518ae1a8f328849e64ea26a222f079< 50d177f90b63ea4138560e500d92be5e4c928186affected
2ac863719e518ae1a8f328849e64ea26a222f079< 6b4e70a428b5a11f56db94047b68e144529fe512affected
2ac863719e518ae1a8f328849e64ea26a222f079< 94b283341f9f3f0ed56a360533766377a01540e0affected
2ac863719e518ae1a8f328849e64ea26a222f079< 439cbbc1519547f9a7b483f0de33b556ebfec901affected
2ac863719e518ae1a8f328849e64ea26a222f079< 6948e570f54f2044dd4da444b10471373a047eebaffected
2ac863719e518ae1a8f328849e64ea26a222f079< 4d54d11b49860686331c58a00f733b16a93edfc4affected
2ac863719e518ae1a8f328849e64ea26a222f079< 622d527decaac0eb65512acada935a0fdc1d0202affected
… +12 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2022-50440

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
drm/vmwgfx: Validate the box size for the snooped cursor
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Validate the box size for the snooped cursor Invalid userspace dma surface copies could potentially overflow the memcpy from the surface to the snooped image leading to crashes. To fix it the dimensions of the copybox have to be validated against the expected size of the snooped cursor.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于未验证复制框尺寸,可能导致内存复制溢出。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux 2ac863719e518ae1a8f328849e64ea26a222f079 ~ ee8d31836cbe7c26e207bfa0a4a726f0a25cfcf6 -
LinuxLinux 3.2 -

II. Public POCs for CVE-2022-50440

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2022-50440

登录查看更多情报信息。

Same Patch Batch · Linux · 2025-10-01 · 169 CVEs total

CVE-2025-399198.8 HIGHwifi: mt76: mt7996: add missing check for rx wcid entries
CVE-2025-399188.8 HIGHwifi: mt76: fix linked list corruption
CVE-2025-398967.8 HIGHaccel/ivpu: Prevent recovery work from being queued during device removal
CVE-2025-399247.8 HIGHerofs: fix invalid algorithm for encoded extents
CVE-2025-399277.8 HIGHceph: fix race condition validating r_parent before applying state
CVE-2025-399067.8 HIGHdrm/amd/display: remove oem i2c adapter on finish
CVE-2025-399087.8 HIGHnet: dev_ioctl: take ops lock in hwtstamp lower paths
CVE-2025-398947.5 HIGHnetfilter: br_netfilter: do not check confirmed bit in br_nf_local_in() after confirm
CVE-2025-398977.5 HIGHnet: xilinx: axienet: Add error handling for RX metadata pointer retrieval
CVE-2025-399027.1 HIGHmm/slub: avoid accessing metadata when pointer is invalid in object_err()
CVE-2025-399287.1 HIGHi2c: rtl9300: ensure data length is within supported range
CVE-2022-50465ext4: fix leaking uninitialized memory in fast-commit journal
CVE-2022-50456btrfs: fix resolving backrefs for inline extent followed by prealloc
CVE-2022-50458clk: tegra: Fix refcount leak in tegra210_clock_init
CVE-2022-50460cifs: Fix xid leak in cifs_flock()
CVE-2022-50459scsi: iscsi: iscsi_tcp: Fix null-ptr-deref while calling getpeername()
CVE-2022-50461net: ethernet: ti: am65-cpsw: Fix PM runtime leakage in am65_cpsw_nuss_ndo_slave_open()
CVE-2022-50462MIPS: vpe-mt: fix possible memory leak while module exiting
CVE-2023-53490mptcp: fix disconnect vs accept race
CVE-2023-53489tcp/udp: Fix memleaks of sk and zerocopy skbs with TX timestamp.

Showing top 20 of 169 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2022-50440

No comments yet


Leave a comment