CVE-2022-50470
In the Linux kernel, the following vulnerability has been resolved:
xhci: Remove device endpoints from bandwidth list when freeing the device
Endpoints are normally deleted from the bandwidth list when they are dropped, before the virt device is freed.
If xHC host is dying or being removed then the endpoints aren't dropped cleanly due to functions returning early to avoid interacting with a non-accessible host controller.
So check and delete endpoints that are still on the bandwidth list when freeing the virt device.
Solves a list_del corruption kernel crash when unbinding xhci-pci, caused by xhci_mem_cleanup() when it later tried to delete already freed endpoints from the bandwidth list.
Leer descripción completaMostrar menos
This only affects hosts that use software bandwidth checking, which currenty is only the xHC in intel Panther Point PCH (Ivy Bridge)
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 7.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.17%
- Percentil entre todas las CVEs puntuadas: 6
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1068Exploitation for Privilege Escalationprivilege escalation85 % - Impacto principal
T1059Command and Scripting Interpreterexecution70 %
Vulnerabilidad de corrupción de memoria (CWE-415) en kernel Linux con acceso local y privilegios de usuario (AV:L/PR:L), permitiendo ejecución de código mediante manipulación de lista de ancho de banda en xhci.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
CWE
- CWE-415
Referencias
- https://git.kernel.org/stable/c/3bf860a41e0f2fcea0ac3aae8f7ef887a7994b70
- https://git.kernel.org/stable/c/5aed5b7c2430ce318a8e62f752f181e66f0d1053
- https://git.kernel.org/stable/c/5e4ce28ad907aa54f13b21d5f1dc490525957b0c
- https://git.kernel.org/stable/c/678d2cc2041cc6ce05030852dce9ad42719abcfc
- https://git.kernel.org/stable/c/8f1cd9633d1f21efc13e8fc75be8f2b6bb85e38c
- https://git.kernel.org/stable/c/c892a81c7424b4f6a660cb9c249d354ccf3afeca
- https://git.kernel.org/stable/c/cebbc8d335d6bcc1316584f779c08f80287c6af8
- https://git.kernel.org/stable/c/f0de39474078adef6ece7a183e34c15ce2c1d8d1
JSON original (NVD)
Mostrar
{
"id": "CVE-2022-50470",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "2e27980e6eb78114c4ecbaad1ba71836e3887d18",
"lessThan": "5e4ce28ad907aa54f13b21d5f1dc490525957b0c",
"versionType": "git"
},
{
"status": "affected",
"version": "2e27980e6eb78114c4ecbaad1ba71836e3887d18",
"lessThan": "f0de39474078adef6ece7a183e34c15ce2c1d8d1",
"versionType": "git"
},
{
"status": "affected",
"version": "2e27980e6eb78114c4ecbaad1ba71836e3887d18",
"lessThan": "cebbc8d335d6bcc1316584f779c08f80287c6af8",
"versionType": "git"
},
{
"status": "affected",
"version": "2e27980e6eb78114c4ecbaad1ba71836e3887d18",
"lessThan": "8f1cd9633d1f21efc13e8fc75be8f2b6bb85e38c",
"versionType": "git"
},
{
"status": "affected",
"version": "2e27980e6eb78114c4ecbaad1ba71836e3887d18",
"lessThan": "678d2cc2041cc6ce05030852dce9ad42719abcfc",
"versionType": "git"
},
{
"status": "affected",
"version": "2e27980e6eb78114c4ecbaad1ba71836e3887d18",
"lessThan": "c892a81c7424b4f6a660cb9c249d354ccf3afeca",
"versionType": "git"
},
{
"status": "affected",
"version": "2e27980e6eb78114c4ecbaad1ba71836e3887d18",
"lessThan": "3bf860a41e0f2fcea0ac3aae8f7ef887a7994b70",
"versionType": "git"
},
{
"status": "affected",
"version": "2e27980e6eb78114c4ecbaad1ba71836e3887d18",
"lessThan": "5aed5b7c2430ce318a8e62f752f181e66f0d1053",
"versionType": "git"
}
],
"programFiles": [
"drivers/usb/host/xhci-mem.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "3.2"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "3.2",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "4.9.332",
"versionType": "semver",
"lessThanOrEqual": "4.9.*"
},
{
"status": "unaffected",
"version": "4.14.298",
"versionType": "semver",
"lessThanOrEqual": "4.14.*"
},
{
"status": "unaffected",
"version": "4.19.264",
"versionType": "semver",
"lessThanOrEqual": "4.19.*"
},
{
"status": "unaffected",
"version": "5.4.223",
"versionType": "semver",
"lessThanOrEqual": "5.4.*"
},
{
"status": "unaffected",
"version": "5.10.153",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.77",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.0.7",
"versionType": "semver",
"lessThanOrEqual": "6.0.*"
},
{
"status": "unaffected",
"version": "6.1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/usb/host/xhci-mem.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2025-10-04T16:15:42.380",
"references": [
{
"url": "https://git.kernel.org/stable/c/3bf860a41e0f2fcea0ac3aae8f7ef887a7994b70",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/5aed5b7c2430ce318a8e62f752f181e66f0d1053",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/5e4ce28ad907aa54f13b21d5f1dc490525957b0c",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/678d2cc2041cc6ce05030852dce9ad42719abcfc",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/8f1cd9633d1f21efc13e8fc75be8f2b6bb85e38c",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/c892a81c7424b4f6a660cb9c249d354ccf3afeca",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/cebbc8d335d6bcc1316584f779c08f80287c6af8",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/f0de39474078adef6ece7a183e34c15ce2c1d8d1",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-415"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nxhci: Remove device endpoints from bandwidth list when freeing the device\n\nEndpoints are normally deleted from the bandwidth list when they are\ndropped, before the virt device is freed.\n\nIf xHC host is dying or being removed then the endpoints aren't dropped\ncleanly due to functions returning early to avoid interacting with a\nnon-accessible host controller.\n\nSo check and delete endpoints that are still on the bandwidth list when\nfreeing the virt device.\n\nSolves a list_del corruption kernel crash when unbinding xhci-pci,\ncaused by xhci_mem_cleanup() when it later tried to delete already freed\nendpoints from the bandwidth list.\n\nThis only affects hosts that use software bandwidth checking, which\ncurrenty is only the xHC in intel Panther Point PCH (Ivy Bridge)"
}
],
"lastModified": "2026-06-17T05:23:37.073",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3DE2F2C8-204B-4A2E-BBAA-90AD498BBF94",
"versionEndExcluding": "4.9.332",
"versionStartIncluding": "3.2"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7140B9A2-EB63-497C-96B1-68A96CD99051",
"versionEndExcluding": "4.14.298",
"versionStartIncluding": "4.10"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8AE23A9F-BF98-4055-AA49-02118B96226D",
"versionEndExcluding": "4.19.264",
"versionStartIncluding": "4.15"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7FE3F72A-5992-4ABB-A961-F834281060A9",
"versionEndExcluding": "5.4.223",
"versionStartIncluding": "4.20"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "62052E35-0E91-4164-BB92-83270CEA0113",
"versionEndExcluding": "5.10.153",
"versionStartIncluding": "5.5"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "756161DE-EFE3-4008-964A-DFE360B188B7",
"versionEndExcluding": "5.15.77",
"versionStartIncluding": "5.11"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "65D387F0-209C-4EAD-98BA-C4B430A840C9",
"versionEndExcluding": "6.0.7",
"versionStartIncluding": "5.16"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.1:rc1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E7E331DA-1FB0-4DEC-91AC-7DA69D461C11"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.1:rc2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "17F0B248-42CF-4AE6-A469-BB1BAE7F4705"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}