CVE-2022-50133 is a NULL pointer dereference vulnerability in the Linux kernel's xHCI USB host controller driver. Specifically, it affects the xhci_plat_remove function, which can lead to a system crash (Oops) during reboot if the shared_hcd pointer is NULL. This vulnerability impacts systems running affected versions of the Linux kernel. This vulnerability has a CVSS score of 5.5 (Medium), indicating that an attacker with local access (AV:L) can trigger the issue with low complexity (AC:L) and no user interaction (UI:N). The primary impact is a denial of service (A:H) due to system instability or crashes, with no confidentiality or integrity impact (C:N, I:N). Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) or community discussion has been identified. It is not listed on the CISA KEV catalog, suggesting it is not a known exploited vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.19, < 5.19.2CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.