CVE-2022-50552
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2022-50552 is a vulnerability in the Linux kernel related to block multi-queue (blk-mq) elevator switch handling during hardware queue reinitialization. The vulnerability was discovered and documented in 2022, affecting various Linux kernel versions (Debian Tracker).

Technical details

The vulnerability occurs when the hardware context's (hctx) run_work races with the elevator switch during hardware queue reinitialization. While the queue is frozen to prevent request allocation, this doesn't stop the hctx work from running. This can lead to the work accessing an elevator pointer that's being torn down. The CVSS v3.1 Base Score is 5.3 with the following metrics: AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H (Red Hat CVE).

Impact

The vulnerability can result in use-after-free errors and kernel panics. When exploited, it can cause system instability through NULL pointer dereference and supervisor read access errors in kernel mode, potentially leading to system crashes (Red Hat CVE).

Mitigation and workarounds

To mitigate this issue, it is recommended to prevent the kyber-iosched module from being loaded. The fix involves using a quiesced elevator switch instead of the previous implementation, ensuring queue work cannot observe a half-torn-down scheduler. Fixed versions are available in various Linux distributions including Debian bookworm (6.1.148-1) and later versions (Debian Tracker).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-40343MEDIUM6.4
  • Linux KernelLinux Kernel
  • linux-riscv
NoYesDec 09, 2025
CVE-2025-40342MEDIUM6.4
  • Linux KernelLinux Kernel
  • linux-azure-5.4
NoYesDec 09, 2025
CVE-2025-40341MEDIUM5.1
  • Linux KernelLinux Kernel
  • kernel-debug-uki-virt-addons
NoYesDec 09, 2025
CVE-2025-40345N/AN/A
  • Linux KernelLinux Kernel
  • bpftool
NoYesDec 12, 2025
CVE-2025-40344N/AN/A
  • Linux KernelLinux Kernel
  • rtla
NoYesDec 09, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management