PT-2025-41023 · Linux+1 · Linux Kernel+1

Published

2022-11-26

·

Updated

2026-04-20

·

CVE-2022-50518

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw exists in the Linux kernel related to locking within the pdc iodc print() firmware call on the parisc architecture. The issue involves a lack of proper protection for the iodc dbuf[] buffer during parallel modifications, potentially leading to buffer overflows. The fix implements the pdc lock spinlock to safeguard against concurrent access and includes length checks to prevent overflows. The iodc retbuf[] buffer was also removed, and code indentation was corrected.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Improper Locking

Weakness Enumeration

Related Identifiers

BDU:2025-12805
CVE-2022-50518
OESA-2026-1950

Affected Products

Debian
Linux Kernel