目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2022-50555— Linux kernel 安全漏洞

AI Predicted 5.5 Difficulty: Moderate EPSS 0.19% · P9

Affected Version Matrix 14

ベンダープロダクトVersion Rangeステータス
LinuxLinux0ef897be12b8b4cf297b6016e79ec97ec90f2cf6< ce69bdac2310152bb70845024d5d704c52aabfc3affected
0ef897be12b8b4cf297b6016e79ec97ec90f2cf6< 24b129aed8730e48f47d852d58d76825ab6f407caffected
0ef897be12b8b4cf297b6016e79ec97ec90f2cf6< 32a3d4660b34ce49ac0162338ebe362098e2f5dfaffected
0ef897be12b8b4cf297b6016e79ec97ec90f2cf6< 7a939503fc32bff4ed60800b73ff7fbb4aea2142affected
0ef897be12b8b4cf297b6016e79ec97ec90f2cf6< cedb41664e27b2cae7e21487f1bee22dcd84037daffected
0ef897be12b8b4cf297b6016e79ec97ec90f2cf6< 82cb4e4612c633a9ce320e1773114875604a3cceaffected
4.17affected
< 4.17unaffected
… +6 more rows
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2022-50555の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
tipc: fix a null-ptr-deref in tipc_topsrv_accept
ソース: NVD (National Vulnerability Database)
脆弱性説明
In the Linux kernel, the following vulnerability has been resolved: tipc: fix a null-ptr-deref in tipc_topsrv_accept syzbot found a crash in tipc_topsrv_accept: KASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f] Workqueue: tipc_rcv tipc_topsrv_accept RIP: 0010:kernel_accept+0x22d/0x350 net/socket.c:3487 Call Trace: <TASK> tipc_topsrv_accept+0x197/0x280 net/tipc/topsrv.c:460 process_one_work+0x991/0x1610 kernel/workqueue.c:2289 worker_thread+0x665/0x1080 kernel/workqueue.c:2436 kthread+0x2e4/0x3a0 kernel/kthread.c:376 ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:306 It was caused by srv->listener that might be set to null by tipc_topsrv_stop() in net .exit whereas it's still used in tipc_topsrv_accept() worker. srv->listener is protected by srv->idr_lock in tipc_topsrv_stop(), so add a check for srv->listener under srv->idr_lock in tipc_topsrv_accept() to avoid the null-ptr-deref. To ensure the lsock is not released during the tipc_topsrv_accept(), move sock_release() after tipc_topsrv_work_stop() where it's waiting until the tipc_topsrv_accept worker to be done. Note that sk_callback_lock is used to protect sk->sk_user_data instead of srv->listener, and it should check srv in tipc_topsrv_listener_data_ready() instead. This also ensures that no more tipc_topsrv_accept worker will be started after tipc_conn_close() is called in tipc_topsrv_stop() where it sets sk->sk_user_data to null.
ソース: NVD (National Vulnerability Database)
CVSS情報
N/A
ソース: NVD (National Vulnerability Database)
脆弱性タイプ
N/A
ソース: NVD (National Vulnerability Database)
脆弱性タイトル
Linux kernel 安全漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于未检查srv->listener空指针,可能导致空指针取消引用。
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
LinuxLinux 0ef897be12b8b4cf297b6016e79ec97ec90f2cf6 ~ ce69bdac2310152bb70845024d5d704c52aabfc3 -
LinuxLinux 4.17 -

II. CVE-2022-50555の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2022-50555のインテリジェンス情報

登录查看更多情报信息。

CVE-2022-50555 补丁与修复 (6)

Same Patch Batch · Linux · 2025-10-07 · 118 CVEs total

CVE-2022-50545r6040: Fix kmemleak in probe and remove
CVE-2023-53658spi: bcm-qspi: return error if neither hif_mspi nor mspi is available
CVE-2023-53657ice: Don't tx before switchdev is fully configured
CVE-2023-53656drivers/perf: hisi: Don't migrate perf to the CPU going to teardown
CVE-2023-53655rcu: Avoid stack overflow due to __rcu_irq_enter_check_tick() being kprobe-ed
CVE-2022-50554blk-mq: avoid double ->queue_rq() because of early timeout
CVE-2022-50553tracing/hist: Fix out-of-bound write on 'action_data.var_ref_idx'
CVE-2022-50552blk-mq: use quiesced elevator switch when reinitializing queues
CVE-2022-50551wifi: brcmfmac: Fix potential shift-out-of-bounds in brcmf_fw_alloc_request()
CVE-2022-50550blk-iolatency: Fix memory leak on add_disk() failures
CVE-2022-50549dm thin: Fix ABBA deadlock between shrink_slab and dm_pool_abort_metadata
CVE-2022-50547media: solo6x10: fix possible memory leak in solo_sysfs_init()
CVE-2022-50548media: i2c: hi846: Fix memory leak in hi846_parse_dt()
CVE-2022-50546ext4: fix uninititialized value in 'ext4_evict_inode'
CVE-2022-50544usb: host: xhci: Fix potential memory leak in xhci_alloc_stream_info()
CVE-2023-53653media: amphion: fix REVERSE_INULL issues reported by coverity
CVE-2022-50536bpf, sockmap: Fix repeated calls to sock_put() when msg has more_data
CVE-2022-50535drm/amd/display: Fix potential null-deref in dm_resume
CVE-2023-53654octeontx2-af: Add validation before accessing cgx and lmac
CVE-2023-53651Input: exc3000 - properly stop timer on shutdown

Showing 20 of 118 CVEs. View all on vendor page →

IV. 関連脆弱性

V. CVE-2022-50555へのコメント

まだコメントはありません


コメントを残す