CVE-2022-50319
BaseFortify
Publication date: 2025-09-15
Last updated on: 2025-12-04
Assigner: kernel.org
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| linux | linux_kernel | From 5.13 (inc) to 5.15.86 (exc) |
| linux | linux_kernel | From 5.16 (inc) to 6.0.16 (exc) |
| linux | linux_kernel | From 6.1 (inc) to 6.1.2 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-NVD-CWE-noinfo |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability in the Linux kernel relates to improper handling of CPU hotplug (cpuhp) state instances in the coresight-trbe driver. Specifically, the functions cpuhp_state_add_instance() and cpuhp_state_remove_instance() must be used in pairs. Failure to do so leads to warnings and errors when removing the coresight-trbe module, as the cpuhp_step list is not empty, causing an error during module removal.
How can this vulnerability impact me? :
The impact of this vulnerability is that attempting to remove the coresight-trbe module from the Linux kernel can result in errors and warnings due to improper cleanup of CPU hotplug state instances. This could potentially lead to instability or resource leaks in the kernel module management process.
How can this vulnerability be detected on my network or system? Can you suggest some commands?
This vulnerability can be detected by observing error logs related to the removal of the coresight-trbe module. Specifically, look for warnings or errors such as 'Removing state 215 which has instances left' during the execution of 'rmmod coresight-trbe'. Monitoring kernel logs (e.g., using 'dmesg' or 'journalctl -k') for such messages can help identify the issue.
What immediate steps should I take to mitigate this vulnerability?
To mitigate this vulnerability, ensure that cpuhp_state_add_instance() and cpuhp_state_remove_instance() are used in pairs when managing cpuhp instances. Avoid removing the cpuhp instance node before removing the cpuhp state to prevent warnings and errors. Applying the patch or update that fixes the coresight-trbe module to correctly remove cpuhp instances before states is recommended.