PT-2025-53932 · Linux · Linux Kernel

Published

2022-07-28

·

Updated

2026-02-24

·

CVE-2022-50814

CVSS v2.0

2.7

Low

VectorAV:A/AC:L/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the Linux kernel’s crypto/hisi zip module related to a mismatch when getting or setting the sgl sge nr variable. The type of sgl sge nr is u16, but it was being accessed using param get/set int functions instead of param get/set ushort. This can lead to a global out-of-bounds read, as reported by KASAN. The buggy address belongs to the sgl sge nr variable within the hisi zip module.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-03585
CVE-2022-50814
SUSE-SU-2026:0263-1
SUSE-SU-2026:0317-1
SUSE-SU-2026:0350-1
SUSE-SU-2026:0369-1
SUSE-SU-2026:0411-1
SUSE-SU-2026:0617-1

Affected Products

Linux Kernel