CVE-2022-50415
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2022-50415 is a vulnerability in the Linux kernel affecting the parisc LED subsystem. The issue was discovered in the starttask() function which fails to check the return value of createsinglethread_workqueue(), potentially leading to a null pointer dereference (NVD, Ubuntu).

Technical details

The vulnerability occurs when starttask() calls createsinglethreadworkqueue() without checking its return value. If createsinglethreadworkqueue() fails and returns NULL, subsequent calls to queuedelayedwork(), queuedelayedworkon(), and queuedelayedwork() continue execution, eventually leading to a null pointer dereference when accessing wq->flags in queue_work() (NVD).

Impact

If exploited, this vulnerability could lead to a system crash due to the null pointer dereference in the kernel's LED subsystem on PA-RISC architecture systems (Ubuntu).

Mitigation and workarounds

The issue has been fixed in multiple Linux kernel versions across different distributions. Ubuntu has released patches for various kernel versions including 5.15.0-69.76 for 22.04 LTS, 5.4.0-144.161 for 20.04 LTS, and 4.15.0-208.220 for 18.04 LTS (Ubuntu).

Additional resources


SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-11266MEDIUM6.8
  • Linux DebianLinux Debian
  • gdcm
NoNoDec 12, 2025
CVE-2025-67897MEDIUM5.3
  • Linux DebianLinux Debian
  • rust-sequoia-openpgp
NoYesDec 14, 2025
CVE-2025-14607MEDIUM5.3
  • Linux DebianLinux Debian
  • dcmtk
NoNoDec 13, 2025
CVE-2025-67749MEDIUM5.3
  • Linux DebianLinux Debian
  • pcsx2
NoNoDec 12, 2025
CVE-2025-40345N/AN/A
  • Linux KernelLinux Kernel
  • bpftool
NoYesDec 12, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management