
Cloud Vulnerability DB
A community-led vulnerabilities database
In the Linux kernel, a vulnerability was identified related to the ARM device tree specification (DTS) for Qualcomm platforms. The issue involves replacing the gcc PXO (Primary Crystal Oscillator) with pxo_board fixed clock declared in the device tree specification. This vulnerability was documented as CVE-2022-50195 and was published on June 18, 2025 (NVD, Wiz).
The vulnerability stems from an incorrect clock source reference in the ARM device tree specification for Qualcomm platforms. The issue occurs when the gcc PXO phandle is used instead of the pxo_board fixed clock in the device tree. Since the gcc driver doesn't provide PXO_SRC functionality for fixed-clock operations, this mismatch in clock source references can trigger a kernel panic when accessed by dependent drivers (Wiz).
When exploited, this vulnerability can cause a kernel panic, effectively resulting in a denial of service condition for the affected system. This occurs when any driver attempts to utilize the incorrectly referenced clock source (Wiz).
The vulnerability has been resolved by replacing the gcc PXO phandle with the pxo_board fixed clock declared in the device tree specification. This correction ensures proper clock source referencing and prevents kernel panics from occurring (Wiz).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."