
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2022-50024 affects the Linux kernel's DMA engine component, specifically the dw-axi-dmac driver. The vulnerability was discovered when the axichandump_lli() function was found to handle NULL LLI (Linked List Item) pointers incorrectly (NVD, Debian Tracker).
The vulnerability exists in the dmaengine subsystem of the Linux kernel, specifically in the Synopsys DesignWare AXI DMA controller driver. During debugging, it was discovered that when the axichandump_lli() function receives a NULL LLI pointer, it attempts to access fields from it instead of properly handling the null case, resulting in a kernel OOPS condition (Wiz).
When triggered, this vulnerability causes a kernel OOPS, which can lead to system instability and potential denial of service conditions in affected Linux systems (Wiz).
The issue has been fixed by modifying the code to properly handle NULL LLI pointers by printing 'NULL LLI' and exiting the function when such cases are encountered. Various Linux distributions have released patches to address this vulnerability, with fixed versions available in newer kernel releases (Debian Tracker).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."