CVE-2022-50063
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2022-50063 is a vulnerability in the Linux kernel's Distributed Switch Architecture (DSA) subsystem, specifically affecting the Felix driver's handling of tagging protocol changes. The vulnerability was discovered in June 2025 and affects the way dsa_tree_change_tag_proto() handles failures during tag protocol changes (NVD, Wiz).

Technical details

The vulnerability occurs when dsa_tree_notify() fails and cannot determine if the failure happened mid-way in a multi-switch tree or in a single-switch tree. This leads to the Felix driver receiving duplicate calls to dsa_tag_8021q_register() without proper unregistration in between, potentially corrupting data structures. The issue can be triggered by forcing an error while in tag_8021q mode, resulting in a kernel NULL pointer dereference at virtual address 0x14 (Debian Tracker, Wiz).

Impact

When exploited, this vulnerability can cause a kernel crash due to NULL pointer dereference, leading to system instability and potential denial of service. The issue affects the operational status of network ports managed by the Felix driver (Wiz).

Mitigation and workarounds

The vulnerability has been fixed in various Linux kernel versions. Debian has addressed this in multiple releases: bullseye (5.10.237-1), bookworm (6.1.140-1), and trixie (6.12.31-1) (Wiz).

Additional resources


SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-22857MEDIUM6.8
  • Linux DebianLinux Debian
  • libwinpr
NoNoJan 14, 2026
CVE-2026-22856MEDIUM6.8
  • Linux DebianLinux Debian
  • freerdp3
NoNoJan 14, 2026
CVE-2026-22859MEDIUM5.6
  • Linux DebianLinux Debian
  • freerdp2
NoNoJan 14, 2026
CVE-2026-22858MEDIUM5.6
  • Linux DebianLinux Debian
  • freerdp-plugins
NoNoJan 14, 2026
CVE-2026-22036LOW3.7
  • JavaScriptJavaScript
  • node-undici
NoYesJan 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management