CVE-2022-50029
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2022-50029 is a denial-of-service vulnerability in the Linux kernel's Qualcomm clock driver (clk: qcom: ipq8074) caused by an improper attempt to disable the gcc_sleep_clk_src clock source. When USB sleep clocks are disabled, the clock framework attempts to also disable the sleep clock source, which cannot be disabled — resulting in a kernel warning (gcc_sleep_clk_src status stuck at 'on') and potential system instability. The vulnerability was published on June 18, 2025, and affects multiple Linux kernel stable branches. It carries a CVSS v3.1 base score of 5.5 (Medium) (Feedly).

Technical details

The root cause is an incorrect clock dependency configuration in the clk-ipq8074.c driver, where gcc_sleep_clk_src is registered in a way that allows the clock framework to attempt disabling it — an operation the hardware does not support (CWE-400: Uncontrolled Resource Consumption / improper state management). When a local user triggers USB sleep clock disable (e.g., by unloading dwc3_qcom or related modules), the clock framework traverses the dependency tree and calls clk_branch_wait() on gcc_sleep_clk_src, which spins indefinitely waiting for the clock to gate, ultimately producing a kernel WARN_ON splat. The fix marks gcc_sleep_clk_src so the framework does not attempt to disable it (Kernel Patches).

Impact

Successful triggering of this bug causes a kernel warning and potential system instability or hang on devices using the Qualcomm IPQ8074 SoC (e.g., Xiaomi AX9000 routers and similar embedded/networking hardware). The impact is limited to availability — there is no confidentiality or integrity impact. An attacker or unprivileged local user with the ability to load/unload USB-related kernel modules could trigger the condition, potentially causing a denial of service (Feedly).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2022-50029. The vulnerability requires local access with low privileges (e.g., ability to manipulate USB/clock-related kernel modules) and is limited to hardware running the Qualcomm IPQ8074 SoC. The EPSS score is approximately 0.024% (0.000240), indicating very low probability of exploitation in the near term. It is not listed in the CISA Known Exploited Vulnerabilities catalog (Feedly).

Mitigation and workarounds

Patches have been backported to multiple stable Linux kernel branches. Fixed versions include: 4.14.291, 4.19.256, 5.4.211, 5.10.138, 5.15.63, and 5.19.4. Administrators running affected kernels on IPQ8074-based devices (such as certain Qualcomm-based routers) should update to a patched kernel version. SUSE has also issued kernel security updates addressing this CVE (SUSE Advisory, Kernel Patches).

Community reactions

SUSE issued multiple kernel security advisories covering CVE-2022-50029 as part of broader Linux kernel update batches in mid-2025. No notable independent researcher commentary or significant social media discussion has been identified for this vulnerability, consistent with its limited scope and hardware-specific nature (SUSE Advisory).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-74732NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-firmware
NoYesAug 22, 2026
CVE-2026-74730NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-debug-devel
NoYesAug 22, 2026
CVE-2026-74726NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-debug-modules
NoYesAug 22, 2026
CVE-2026-74719NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-modules-partner
NoYesAug 22, 2026
CVE-2026-74717NONEN/A
  • Linux Kernel logoLinux Kernel
  • rtla
NoYesAug 22, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management