PT-2025-38179 · Linux+4 · Linux Kernel+4

Published

2022-11-29

·

Updated

2025-10-23

·

CVE-2022-50369

CVSS v2.0

6.0

Medium

VectorAV:L/AC:H/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A null-ptr-deref issue exists in the vkms release() function within the drm/vkms module of the Linux kernel. This occurs when attempting to destroy a workqueue (composer workq) that has not been allocated, specifically during an out-of-memory (OOM) event. The issue is triggered during the destruction of the workqueue in vkms release(), leading to a null pointer dereference. The call trace indicates the issue originates from the destroy workqueue() function.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

BDU:2026-05976
CESA-2023_7077
CESA-2025_13960
CESA-2025_13961
CVE-2022-50369
RHSA-2023:6583
RHSA-2023:7077
RHSA-2023_6583
RHSA-2023_7077
RHSA-2025:13960
RHSA-2025:13961
RHSA-2025_13960
RHSA-2025_13961
SUSE-SU-2025:03615-1
SUSE-SU-2025:03628-1
SUSE-SU-2025:3716-1
SUSE-SU-2025:3761-1

Affected Products

Astra Linux
Centos
Linux Kernel
Red Hat
Suse