CVE-2022-50132
Severity CVSS v4.0:
Pending analysis
Type:
CWE-476
NULL Pointer Dereference
Publication date:
18/06/2025
Last modified:
18/11/2025
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
usb: cdns3: change place of &#39;priv_ep&#39; assignment in cdns3_gadget_ep_dequeue(), cdns3_gadget_ep_enable()<br />
<br />
If &#39;ep&#39; is NULL, result of ep_to_cdns3_ep(ep) is invalid pointer<br />
and its dereference with priv_ep->cdns3_dev may cause panic.<br />
<br />
Found by Linux Verification Center (linuxtesting.org) with SVACE.
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.4 (including) | 5.10.137 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.11 (including) | 5.15.61 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.16 (including) | 5.18.18 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.19 (including) | 5.19.2 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/7af83bb516d7aa4f96835288e4aeda21d7aa2a17
- https://git.kernel.org/stable/c/bfa0201468587072454dba7933e4a4a7be44467a
- https://git.kernel.org/stable/c/c3ffc9c4ca44bfe9562166793d133e1fb0630ea6
- https://git.kernel.org/stable/c/d342203df9f2d0851b4acd9ed577d73d10eade77
- https://git.kernel.org/stable/c/eb82c0382285ee17a9966aaab27b8becb08eb1ac



