CVE-2022-50132

Severity CVSS v4.0:
Pending analysis
Type:
CWE-476 NULL Pointer Dereference
Publication date:
18/06/2025
Last modified:
18/11/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> usb: cdns3: change place of &amp;#39;priv_ep&amp;#39; assignment in cdns3_gadget_ep_dequeue(), cdns3_gadget_ep_enable()<br /> <br /> If &amp;#39;ep&amp;#39; is NULL, result of ep_to_cdns3_ep(ep) is invalid pointer<br /> and its dereference with priv_ep-&gt;cdns3_dev may cause panic.<br /> <br /> Found by Linux Verification Center (linuxtesting.org) with SVACE.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.4 (including) 5.10.137 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.11 (including) 5.15.61 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.16 (including) 5.18.18 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.19 (including) 5.19.2 (excluding)