Skip to main content

Boteraser | Website and Server Security Solutions

🛡️ CVE-2022-50828 — kernel

⚪ Unknown ✅ No Known Exploit NVD
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

clk: zynqmp: Fix stack-out-of-bounds in strncpy`

In the Linux kernel, the following vulnerability has been resolved:

clk: zynqmp: Fix stack-out-of-bounds in strncpy`

"BUG: KASAN: stack-out-of-bounds in strncpy+0x30/0x68"

Linux-ATF interface is using 16 bytes of SMC payload. In case clock name is

longer than 15 bytes, string terminated NULL character will not be received

by Linux. Add explicit NULL character at last byte to fix issues when clock

name is longer.

This fixes below bug reported by KASAN:

==================================================================

BUG: KASAN: stack-out-of-bounds in strncpy+0x30/0x68

Read of size 1 at addr ffff0008c89a7410 by task swapper/0/1

CPU: 1 PID: 1 Comm: swapper/0 Not tainted 5.4.0-00396-g81ef9e7-dirty #3

Hardware name: Xilinx Versal vck190 Eval board revA (QSPI) (DT)

Call trace:

dump_backtrace+0x0/0x1e8

show_stack+0x14/0x20

dump_stack+0xd4/0x108

print_address_description.isra.0+0xbc/0x37c

__kasan_report+0x144/0x198

kasan_report+0xc/0x18

__asan_load1+0x5c/0x68

strncpy+0x30/0x68

zynqmp_clock_probe+0x238/0x7b8

platform_drv_probe+0x6c/0xc8

really_probe+0x14c/0x418

driver_probe_device+0x74/0x130

__device_attach_driver+0xc4/0xe8

bus_for_each_drv+0xec/0x150

__device_attach+0x160/0x1d8

device_initial_probe+0x10/0x18

bus_probe_device+0xe0/0xf0

device_add+0x528/0x950

of_device_add+0x5c/0x80

of_platform_device_create_pdata+0x120/0x168

of_platform_bus_create+0x244/0x4e0

of_platform_populate+0x50/0xe8

zynqmp_firmware_probe+0x370/0x3a8

platform_drv_probe+0x6c/0xc8

really_probe+0x14c/0x418

driver_probe_device+0x74/0x130

device_driver_attach+0x94/0xa0

__driver_attach+0x70/0x108

bus_for_each_dev+0xe4/0x158

driver_attach+0x30/0x40

bus_add_driver+0x21c/0x2b8

driver_register+0xbc/0x1d0

__platform_driver_register+0x7c/0x88

zynqmp_firmware_driver_init+0x1c/0x24

do_one_initcall+0xa4/0x234

kernel_init_freeable+0x1b0/0x24c

kernel_init+0x10/0x110

ret_from_fork+0x10/0x18

The buggy address belongs to the page:

page:ffff0008f9be1c88 refcount:0 mapcount:0 mapping:0000000000000000 index:0x0

raw: 0008d00000000000 ffff0008f9be1c90 ffff0008f9be1c90 0000000000000000

raw: 0000000000000000 0000000000000000 00000000ffffffff

page dumped because: kasan: bad access detected

addr ffff0008c89a7410 is located in stack of task swapper/0/1 at offset 112 in frame:

zynqmp_clock_probe+0x0/0x7b8

this frame has 3 objects:

[32, 44) 'response'

[64, 80) 'ret_payload'

[96, 112) 'name'

Memory state around the buggy address:

ffff0008c89a7300: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

ffff0008c89a7380: 00 00 00 00 f1 f1 f1 f1 00 04 f2 f2 00 00 f2 f2

>ffff0008c89a7400: 00 00 f3 f3 00 00 00 00 00 00 00 00 00 00 00 00

^

ffff0008c89a7480: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

ffff0008c89a7500: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

==================================================================

Affected software

CVE-2022-50828 is recorded against 2 packages.

  • kernel (from 5.20.0 up to 6.0.3)
  • unknown

Timeline and source

Published on 30 December 2025 and last revised on 12 August 2026. No public exploit is currently recorded for this entry. Record sourced from NVD.

References

git.kernel.org (Web)
git.kernel.org (Web)
git.kernel.org (Web)
git.kernel.org (Web)
git.kernel.org (Web)
git.kernel.org (Web)
github.com (Advisory)
nvd.nist.gov (Advisory)
git.kernel.org (Package)

Other advisories for this package

kernel has other advisories on record. If you are patching this one, these are worth checking on the same host:

CVE-2022-50828 on other distributions

Each distribution ships its own build and its own fixed version. Pick the one you run:

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source NVD
Published 2025-12-30
Updated 2026-08-20
Modified 2026-08-12
Fix URL N/A

Affected Packages

Software From version Fixed in
kernel 5.20.0 6.0.3
unknown

Similar Threats

Free Vulnerability Check

Is your site affected by CVE-2022-50828?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against CVE-2022-50828 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesCVECVE 2022