PT-2025-43074 · Linux+1 · Linux Kernel+1

Published

2022-11-07

·

Updated

2025-12-04

·

CVE-2022-50564

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel contains an issue related to the return type of the netiucv tx() function. With the kernel control flow integrity (kCFI) enabled (CONFIG CFI CLANG), indirect call targets are validated against the expected function pointer prototype to mitigate Return-Oriented Programming (ROP) attacks. A mismatch in the expected and actual return types can lead to a kernel panic or thread termination. The ndo start xmit() function within the struct net device ops structure expects a return type of netdev tx t, but the netiucv tx() function currently returns an integer (int). This discrepancy can trigger a control flow integrity failure if the ARCH SUPPORTS CFI CLANG configuration option is selected. The issue also involves the removal of a no-longer-relevant comment block.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-04860
CVE-2022-50564
SUSE-SU-2025:4111-1
SUSE-SU-2025:4139-1
SUSE-SU-2025:4149-1
SUSE-SU-2025:4189-1
SUSE-SU-2025:4320-1

Affected Products

Linux Kernel
Suse