CVE-2022-50133
Linux Kernel vulnerability analysis and mitigation

Overview

A NULL pointer dereference vulnerability (CVE-2022-50133) was discovered in the Linux kernel's USB subsystem, specifically in the xhci_plat_remove function. The vulnerability was introduced after commit 4736ebd7fcaff1eb8481c140ba494962847d6e0a which made it possible for xhci->shared_hcd to be NULL when either root hub has no ports (NVD).

Technical details

The vulnerability occurs in the USB subsystem's XHCI platform driver. When the system attempts to remove the USB host controller during shutdown or reboot, the code fails to properly check for a NULL pointer before dereferencing xhci->shared_hcd. This condition manifests as a kernel oops with a NULL pointer dereference at virtual address 0x3b8 during system shutdown (Wiz).

Impact

When triggered, this vulnerability causes a kernel panic during system shutdown or reboot, resulting in an ungraceful system halt. This can potentially lead to data loss if there are any pending write operations, and affects system stability (Wiz).

Mitigation and workarounds

The vulnerability has been fixed in various Linux distributions through their security updates. Debian has addressed this in version 6.1.137-1~deb11u1 for bullseye (security). Users are advised to update their systems to the patched versions available through their distribution's package management system (Debian Tracker).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-71142N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k-modules-internal
NoNoJan 14, 2026
CVE-2025-71137N/AN/A
  • Linux KernelLinux Kernel
  • libperf-devel
NoYesJan 14, 2026
CVE-2025-71135N/AN/A
  • Linux KernelLinux Kernel
  • libperf-devel
NoNoJan 14, 2026
CVE-2025-71134N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k-devel
NoNoJan 14, 2026
CVE-2025-71133N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k-debug-modules-partner
NoYesJan 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management