CVE-2022-50319
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2022-50319 is a denial-of-service vulnerability in the Linux kernel's CoreSight TRBE (Trace Buffer Extension) driver, caused by a mismatched CPU hotplug instance lifecycle. Specifically, cpuhp_state_add_instance() and cpuhp_state_remove_instance() are not called in pairs during module removal, leaving the cpuhp_step list non-empty and triggering a kernel warning. Affected kernel versions include 5.13 through 5.15.85, 5.16 through 6.0.15, and 6.1 through 6.1.1. It was publicly disclosed on September 15, 2025, and carries a CVSS v3.1 base score of 5.5 (Medium) (Red Hat Advisory, Red Hat Bugzilla).

Technical details

The root cause is improper resource cleanup (CWE-459: Incomplete Cleanup) in the arm_trbe_device_remove() function of the coresight-trbe kernel module. When the module is unloaded via rmmod coresight-trbe, the CPU hotplug instance node is not removed before the CPU hotplug state itself is torn down, violating the required pairing of cpuhp_state_add_instance() and cpuhp_state_remove_instance(). This triggers a kernel warning — "Error: Removing state 215 which has instances left" — and an associated call trace through __cpuhp_remove_state_cpuslocked. The attack vector is local and requires low privileges (e.g., the ability to unload kernel modules), with no user interaction needed (Red Hat Bugzilla, Red Hat Advisory).

Impact

Successful exploitation results in system instability and a denial-of-service condition on ARM64 systems equipped with the CoreSight TRBE hardware tracing subsystem. There is no confidentiality or integrity impact; the vulnerability exclusively affects availability. The kernel warning and improper state cleanup during module unloading can cause unexpected behavior or system instability, particularly on embedded or server ARM64 platforms using hardware trace capabilities (Red Hat Bugzilla, Red Hat Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.018%, reflecting a very low probability of exploitation in the near term. Exploitation requires local access with sufficient privileges to unload kernel modules, significantly limiting the attack surface (Red Hat Advisory).

Mitigation and workarounds

The Linux kernel project has released patches addressing this vulnerability in the following stable versions: 5.15.86, 6.0.16, and 6.1.2. Users should update to one of these or any later kernel release. As a temporary workaround, administrators can avoid unloading the coresight-trbe module on affected systems and monitor kernel logs for warnings related to CPU hotplug state management. Patches are available via the upstream kernel stable tree (Red Hat Bugzilla, Kernel Patch 5.15, Kernel Patch 6.0, Kernel Patch 6.1).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64597CRITICAL9.8
  • Linux Kernel logoLinux Kernel
  • linux-aws
NoYesAug 06, 2026
CVE-2026-68480HIGH8.8
  • Linux Kernel logoLinux Kernel
  • rv
NoYesAug 06, 2026
CVE-2026-64598HIGH8.8
  • Linux Kernel logoLinux Kernel
  • linux-intel-iotg
NoYesAug 06, 2026
CVE-2026-64604HIGH7.7
  • Linux Kernel logoLinux Kernel
  • linux-hwe-5.15
NoYesAug 06, 2026
CVE-2026-64603NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-gcp-6.8
NoYesAug 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management