CVE-2022-50116
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2022-50116 is a vulnerability in the Linux kernel's TTY subsystem, specifically affecting the n_gsm line discipline component. The vulnerability was disclosed on June 18, 2025, and involves a deadlock and link starvation issue in the outgoing data path of the GSM line discipline (NVD, Debian Tracker).

Technical details

The vulnerability stems from the implementation where control and user packets are queued and processed to the line discipline in the same code path, causing hard coupling between upper and lower layers. This design leads to deadlocks during line discipline congestion and causes data channels to starve the control channel under high transmission loads. The issue manifests as a spinlock recursion bug that can be triggered during data transmission, particularly affecting the serial8250_ports interface (NVD).

Impact

The vulnerability can result in system deadlocks and communication failures in affected systems. When triggered, it can cause spinlock recursion on the CPU, leading to system instability and potential denial of service conditions. Additionally, the starvation of control channels can result in timeouts and link hangups during line discipline congestion (NVD).

Mitigation and workarounds

The fix introduces an additional control channel data queue to prevent timeouts and link hangups during line discipline congestion. The solution processes this queue before the user channel data queue in gsm_data_kick() with highest priority. The patch also moves the queue to line discipline data path into a workqueue and implements changes to gsm_dlci_data_sweep() to manage the transmission queue effectively (NVD).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-71142N/AN/A
  • Linux KernelLinux Kernel
  • kernel-uki-virt-addons
NoNoJan 14, 2026
CVE-2025-71137N/AN/A
  • Linux KernelLinux Kernel
  • linux-azure-6.14
NoYesJan 14, 2026
CVE-2025-71135N/AN/A
  • Linux KernelLinux Kernel
  • kernel-debug-modules-internal
NoNoJan 14, 2026
CVE-2025-71134N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k-debug-modules-core
NoNoJan 14, 2026
CVE-2025-71133N/AN/A
  • Linux KernelLinux Kernel
  • linux-ibm-5.15
NoYesJan 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management