CVE-2022-50426
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2022-50426 is a vulnerability in the Linux kernel's remoteproc subsystem, specifically in the imx_dsp_rproc component, discovered and disclosed on October 1, 2025. The vulnerability affects the workqueue execution timing in relation to remoteproc stopping operations, potentially leading to kernel crashes (NVD, RedHat).

Technical details

The vulnerability occurs when the workqueue executes late after remoteproc is stopped or stopping, causing access to already released resources (rpmsg device and endpoint) in rproc_stop_subdevices(). This leads to a kernel dump when rproc_vq_interrupt() attempts to access these released resources. The vulnerability has been assigned a CVSS v3.1 score of 6.0 with vector CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:H/A:H (RedHat).

Impact

The vulnerability can cause kernel crashes when the workqueue attempts to access released resources during the remoteproc stopping process. This requires elevated privileges (CAP_SYS_ADMIN) to exploit, as it depends on the ability to stop/restart the DSP or send messages that trigger the virtqueue handler via remoteproc (RedHat).

Mitigation and workarounds

The vulnerability has been resolved by adding mutex protection in imx_dsp_rproc_vq_work(). The fix includes skipping the call to rproc_vq_interrupt() if the state is not running. Additionally, the flush workqueue operation has been removed from rproc stop due to the same resource release concerns (NVD).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-71142N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k-core
NoNoJan 14, 2026
CVE-2025-71137N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k
NoYesJan 14, 2026
CVE-2025-71135N/AN/A
  • Linux KernelLinux Kernel
  • rv
NoNoJan 14, 2026
CVE-2025-71134N/AN/A
  • Linux KernelLinux Kernel
  • kernel-zfcpdump
NoNoJan 14, 2026
CVE-2025-71133N/AN/A
  • Linux KernelLinux Kernel
  • kernel-rt-debug
NoYesJan 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management