CVE-2022-50362 is a vulnerability in the Linux kernel's dmaengine hisilicon component, specifically affecting the handling of DMA channels. It arises when multiple threads attempt to use a single DMA channel, leading to a data race condition that can cause system crashes (Oops) and hangs. This issue is due to threads prematurely rewriting channel descriptors, causing the driver to use incorrect descriptors and resulting in transmission timeouts. The vulnerability is rated Medium severity with a CVSS score of 5.5. It has a local attack vector (AV:L) and low attack complexity (AC:L), requiring local user privileges (PR:L). The primary impact is high availability loss (A:H) due to system instability, with no impact on confidentiality or integrity. Currently, there is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit, Nuclei, or ExploitDB. The vulnerability has also received minimal community discussion and media coverage, indicating a low level of public awareness or concern at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.6, < 5.10.150CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.11, < 5.15.75CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.16, < 5.19.17CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.0, < 6.0.3CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.