PT-2025-25970 · Linux+4 · Linux Kernel+4

Published

2022-08-15

·

Updated

2025-07-15

·

CVE-2022-50044

CVSS v2.0

6.0

Medium

VectorAV:L/AC:H/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A vulnerability in the Linux kernel has been resolved, related to the qrtr (Qualcomm Remote Transport) module. The issue arises when the MHI (Mobile Hardware Interface) channel generates events or interrupts immediately after being enabled, leading to two potential race conditions. The first race condition occurs when an event is dropped by the qcom mhi qrtr dl callback() function because dev set drvdata() has not been performed yet, preventing qrtr-ns from enumerating services in the device. The second race condition happens when an event occurs after dev set drvdata() but before qrtr endpoint register(), causing a kernel panic due to accessing a wrong pointer in qcom mhi qrtr dl callback(). This is because the endpoint has not been created yet.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-02577
CESA-2023_2951
CVE-2022-50044
RHSA-2023:2458
RHSA-2023:2951
RHSA-2023_2458
RHSA-2023_2951
RHSA-2025:14744
RHSA-2025:14749
SUSE-SU-2025:02264-1
SUSE-SU-2025:02321-1
SUSE-SU-2025:2264-1
SUSE-SU-2025_02264-1

Affected Products

Astra Linux
Centos
Linux Kernel
Red Hat
Suse