CVE-2022-50332
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2022-50332 is a Linux kernel vulnerability in the video/aperture subsystem where sysfb_disable() is not called before removing PCI devices in aperture_remove_conflicting_pci_devices(). This omission allows the simpledrm driver to bind to simple-framebuffer devices after a hardware driver has already taken over the hardware, causing both drivers to interfere with each other and producing undefined behavior. The vulnerability affects Linux kernel versions 6.0.3 through 6.0.5 (i.e., versions starting from 6.0.3 and before 6.0.6) and was publicly disclosed on September 15, 2025. It carries a CVSS v3.1 base score of 5.5 (Medium) (Red Hat Advisory, Red Hat Bugzilla).

Technical details

The root cause is a flawed stable-branch backport: commit 5e0137612430 ("video/aperture: Disable and unregister sysfb devices via aperture helpers") was backported from the v6.0-rc1 mainline to stable v6.0.3, but the backport omitted a necessary change to aperture_remove_conflicting_pci_devices() that calls sysfb_disable() prior to PCI device removal. In mainline, the function does not exist due to a broader patch series reworking fbdev framebuffer ownership, so mainline is unaffected. The missing call means simpledrm can concurrently access framebuffer hardware already claimed by a dedicated hardware driver, leading to RCU (Read-Copy-Update) stalls, modesetting errors, and undefined kernel behavior (CWE classification consistent with improper resource management). Exploitation requires local access with low privileges (Red Hat Bugzilla).

Impact

Successful triggering of this vulnerability results in a Denial of Service (DoS) condition on affected systems. Concurrent driver interference between simpledrm and the hardware graphics driver can cause RCU stalls, system hangs, graphics rendering failures, and undefined kernel behavior. There is no confidentiality or integrity impact; the vulnerability is limited to availability, affecting the stability of the graphics subsystem and potentially the entire system (Red Hat Advisory, Red Hat Bugzilla).

Mitigation and workarounds

The fix is to update the Linux kernel to version 6.0.6 or later, which includes the corrected aperture_remove_conflicting_pci_devices() function that properly calls sysfb_disable() before removing PCI devices. The upstream patch is available at the kernel stable repository (commit 25a6688f27ff54f97adf7cce1d7e18c38bf51eb4). Users on affected stable kernel versions (6.0.3–6.0.5) should apply vendor-provided kernel updates as soon as available and monitor system stability, particularly after graphics driver initialization (Red Hat Bugzilla, Kernel Patch).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64181HIGH7.8
  • Linux Kernel logoLinux Kernel
  • linux-azure-4.15
NoYesJul 19, 2026
CVE-2026-64186NONEN/A
  • Linux Kernel logoLinux Kernel
  • libperf
NoYesJul 19, 2026
CVE-2026-64183NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-aws-6.14
NoYesJul 19, 2026
CVE-2026-64182NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-oracle-6.17
NoYesJul 19, 2026
CVE-2026-64180NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-5.4
NoYesJul 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management