🛡️ CVE-2022-50556 — kernel

⚪ Unknown ✅ No Known Exploit NVD
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

drm: Fix potential null-ptr-deref due to drmm_mode_config_init()

In the Linux kernel, the following vulnerability has been resolved:

drm: Fix potential null-ptr-deref due to drmm_mode_config_init()

drmm_mode_config_init() will call drm_mode_create_standard_properties()

and won't check the ret value. When drm_mode_create_standard_properties()

failed due to alloc, property will be a NULL pointer and may causes the

null-ptr-deref. Fix the null-ptr-deref by adding the ret value check.

Found null-ptr-deref while testing insert module bochs:

general protection fault, probably for non-canonical address

0xdffffc000000000c: 0000 [#1] SMP KASAN PTI

KASAN: null-ptr-deref in range [0x0000000000000060-0x0000000000000067]

CPU: 3 PID: 249 Comm: modprobe Not tainted 6.1.0-rc1+ #364

Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS

rel-1.15.0-0-g2dd4b9b3f840-prebuilt.qemu.org 04/01/2014

RIP: 0010:drm_object_attach_property+0x73/0x3c0 [drm]

Call Trace:

<TASK>

__drm_connector_init+0xb6c/0x1100 [drm]

bochs_pci_probe.cold.11+0x4cb/0x7fe [bochs]

pci_device_probe+0x17d/0x340

really_probe+0x1db/0x5d0

__driver_probe_device+0x1e7/0x250

driver_probe_device+0x4a/0x120

__driver_attach+0xcd/0x2c0

bus_for_each_dev+0x11a/0x1b0

bus_add_driver+0x3d7/0x500

driver_register+0x18e/0x320

do_one_initcall+0xc4/0x3e0

do_init_module+0x1b4/0x630

load_module+0x5dca/0x7230

__do_sys_finit_module+0x100/0x170

do_syscall_64+0x3f/0x90

entry_SYSCALL_64_after_hwframe+0x63/0xcd

RIP: 0033:0x7ff65af9f839

Affected software

CVE-2022-50556 is recorded against 2 packages.

  • kernel (from 6.2.0 up to 6.2.3)
  • unknown

Timeline and source

Published on 22 October 2025 and last revised on 12 August 2026. No public exploit is currently recorded for this entry. Record sourced from NVD.

References

git.kernel.org (Web)
git.kernel.org (Web)
git.kernel.org (Web)
git.kernel.org (Web)
git.kernel.org (Web)
github.com (Advisory)
nvd.nist.gov (Advisory)
git.kernel.org (Package)

CVE-2022-50556 on other distributions

Each distribution ships its own build and its own fixed version. Pick the one you run:

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source NVD
Published 2025-10-22
Updated 2026-08-20
Modified 2026-08-12
Fix URL N/A

Affected Packages

Software From version Fixed in
kernel 6.2.0 6.2.3
unknown

Similar Threats

Free Vulnerability Check

Is your site affected by CVE-2022-50556?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against CVE-2022-50556 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesCVECVE 2022