CVE-2022-50195
Linux Debian vulnerability analysis and mitigation

Overview

In the Linux kernel, a vulnerability was identified related to the ARM device tree specification (DTS) for Qualcomm platforms. The issue involves replacing the gcc PXO (Primary Crystal Oscillator) with pxo_board fixed clock declared in the device tree specification. This vulnerability was documented as CVE-2022-50195 and was published on June 18, 2025 (NVD, Wiz).

Technical details

The vulnerability stems from an incorrect clock source reference in the ARM device tree specification for Qualcomm platforms. The issue occurs when the gcc PXO phandle is used instead of the pxo_board fixed clock in the device tree. Since the gcc driver doesn't provide PXO_SRC functionality for fixed-clock operations, this mismatch in clock source references can trigger a kernel panic when accessed by dependent drivers (Wiz).

Impact

When exploited, this vulnerability can cause a kernel panic, effectively resulting in a denial of service condition for the affected system. This occurs when any driver attempts to utilize the incorrectly referenced clock source (Wiz).

Mitigation and workarounds

The vulnerability has been resolved by replacing the gcc PXO phandle with the pxo_board fixed clock declared in the device tree specification. This correction ensures proper clock source referencing and prevents kernel panics from occurring (Wiz).

Additional resources


SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-33230HIGH7.3
  • Linux DebianLinux Debian
  • nvidia-cuda-toolkit
NoNoJan 20, 2026
CVE-2025-33229HIGH7.3
  • Linux DebianLinux Debian
  • nvidia-cuda-toolkit
NoNoJan 20, 2026
CVE-2025-33228HIGH7.3
  • Linux DebianLinux Debian
  • nvidia-cuda-toolkit
NoNoJan 20, 2026
CVE-2025-33231MEDIUM6.7
  • Linux DebianLinux Debian
  • nvidia-cuda-toolkit
NoNoJan 20, 2026
CVE-2025-15281N/AN/A
  • WolfiWolfi
  • glibc-langpack-anp
NoYesJan 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management