« Volver al listado

CVE-2022-50614

Estado: AplazadaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

misc: pci_endpoint_test: Fix pci_endpoint_test_{copy,write,read}() panic

The dma_map_single() doesn't permit zero length mapping. It causes a follow panic.

A panic was reported on arm64:

To fix it, this patch adds a checking the payload length if it is zero.

Detalles técnicos trazas, registros y código del informe original
[   60.137988] ------------[ cut here ]------------
[   60.142630] kernel BUG at kernel/dma/swiotlb.c:624!
[   60.147508] Internal error: Oops - BUG: 0 [#1] PREEMPT SMP
[   60.152992] Modules linked in: dw_hdmi_cec crct10dif_ce simple_bridge rcar_fdp1 vsp1 rcar_vin videobuf2_vmalloc rcar_csi2 v4l
2_mem2mem videobuf2_dma_contig videobuf2_memops pci_endpoint_test videobuf2_v4l2 videobuf2_common rcar_fcp v4l2_fwnode v4l2_asyn
c videodev mc gpio_bd9571mwv max9611 pwm_rcar ccree at24 authenc libdes phy_rcar_gen3_usb3 usb_dmac display_connector pwm_bl
[   60.186252] CPU: 0 PID: 508 Comm: pcitest Not tainted 6.0.0-rc1rpci-dev+ #237
[   60.193387] Hardware name: Renesas Salvator-X 2nd version board based on r8a77951 (DT)
[   60.201302] pstate: 00000005 (nzcv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)
[   60.208263] pc : swiotlb_tbl_map_single+0x2c0/0x590
[   60.213149] lr : swiotlb_map+0x88/0x1f0
[   60.216982] sp : ffff80000a883bc0
[   60.220292] x29: ffff80000a883bc0 x28: 0000000000000000 x27: 0000000000000000
[   60.227430] x26: 0000000000000000 x25: ffff0004c0da20d0 x24: ffff80000a1f77c0
[   60.234567] x23: 0000000000000002 x22: 0001000040000010 x21: 000000007a000000
[   60.241703] x20: 0000000000200000 x19: 0000000000000000 x18: 0000000000000000
[   60.248840] x17: 0000000000000000 x16: 0000000000000000 x15: ffff0006ff7b9180
[   60.255977] x14: ffff0006ff7b9180 x13: 0000000000000000 x12: 0000000000000000
[   60.263113] x11: 0000000000000000 x10: 0000000000000000 x9 : 0000000000000000
[   60.270249] x8 : 0001000000000010 x7 : ffff0004c6754b20 x6 : 0000000000000000
[   60.277385] x5 : ffff0004c0da2090 x4 : 0000000000000000 x3 : 0000000000000001
[   60.284521] x2 : 0000000040000000 x1 : 0000000000000000 x0 : 0000000040000010
[   60.291658] Call trace:
[   60.294100]  swiotlb_tbl_map_single+0x2c0/0x590
[   60.298629]  swiotlb_map+0x88/0x1f0
[   60.302115]  dma_map_page_attrs+0x188/0x230
[   60.306299]  pci_endpoint_test_ioctl+0x5e4/0xd90 [pci_endpoint_test]
[   60.312660]  __arm64_sys_ioctl+0xa8/0xf0
[   60.316583]  invoke_syscall+0x44/0x108
[   60.320334]  el0_svc_common.constprop.0+0xcc/0xf0
[   60.325038]  do_el0_svc+0x2c/0xb8
[   60.328351]  el0_svc+0x2c/0x88
[   60.331406]  el0t_64_sync_handler+0xb8/0xc0
[   60.335587]  el0t_64_sync+0x18c/0x190
[   60.339251] Code: 52800013 d2e00414 35fff45c d503201f (d4210000)
[   60.345344] ---[ end trace 0000000000000000 ]---

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-50614",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "343dc693f7b79885197f9d37dd8b711b0e3ffc8f",
              "lessThan": "0df206bdc6204b758585bbe159a55e23e7917b13",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "343dc693f7b79885197f9d37dd8b711b0e3ffc8f",
              "lessThan": "e5ebcbb4f967af2083d409271aaf7c7d8351603f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "343dc693f7b79885197f9d37dd8b711b0e3ffc8f",
              "lessThan": "279116cb0bc5cd8af65d6a00ffe074bd09842f88",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "343dc693f7b79885197f9d37dd8b711b0e3ffc8f",
              "lessThan": "6c01739c2aba19553beb20491b05515af9246f0f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "343dc693f7b79885197f9d37dd8b711b0e3ffc8f",
              "lessThan": "8e30538eca016de8e252bef174beadecd64239f0",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/misc/pci_endpoint_test.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.15"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "4.15",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.148",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.74",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "5.19.16",
              "versionType": "semver",
              "lessThanOrEqual": "5.19.*"
            },
            {
              "status": "unaffected",
              "version": "6.0.2",
              "versionType": "semver",
              "lessThanOrEqual": "6.0.*"
            },
            {
              "status": "unaffected",
              "version": "6.1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/misc/pci_endpoint_test.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2025-12-08T02:15:47.063",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/0df206bdc6204b758585bbe159a55e23e7917b13",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/279116cb0bc5cd8af65d6a00ffe074bd09842f88",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6c01739c2aba19553beb20491b05515af9246f0f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/8e30538eca016de8e252bef174beadecd64239f0",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e5ebcbb4f967af2083d409271aaf7c7d8351603f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Deferred",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmisc: pci_endpoint_test: Fix pci_endpoint_test_{copy,write,read}() panic\n\nThe dma_map_single() doesn't permit zero length mapping. It causes a follow\npanic.\n\nA panic was reported on arm64:\n\n[   60.137988] ------------[ cut here ]------------\n[   60.142630] kernel BUG at kernel/dma/swiotlb.c:624!\n[   60.147508] Internal error: Oops - BUG: 0 [#1] PREEMPT SMP\n[   60.152992] Modules linked in: dw_hdmi_cec crct10dif_ce simple_bridge rcar_fdp1 vsp1 rcar_vin videobuf2_vmalloc rcar_csi2 v4l\n2_mem2mem videobuf2_dma_contig videobuf2_memops pci_endpoint_test videobuf2_v4l2 videobuf2_common rcar_fcp v4l2_fwnode v4l2_asyn\nc videodev mc gpio_bd9571mwv max9611 pwm_rcar ccree at24 authenc libdes phy_rcar_gen3_usb3 usb_dmac display_connector pwm_bl\n[   60.186252] CPU: 0 PID: 508 Comm: pcitest Not tainted 6.0.0-rc1rpci-dev+ #237\n[   60.193387] Hardware name: Renesas Salvator-X 2nd version board based on r8a77951 (DT)\n[   60.201302] pstate: 00000005 (nzcv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n[   60.208263] pc : swiotlb_tbl_map_single+0x2c0/0x590\n[   60.213149] lr : swiotlb_map+0x88/0x1f0\n[   60.216982] sp : ffff80000a883bc0\n[   60.220292] x29: ffff80000a883bc0 x28: 0000000000000000 x27: 0000000000000000\n[   60.227430] x26: 0000000000000000 x25: ffff0004c0da20d0 x24: ffff80000a1f77c0\n[   60.234567] x23: 0000000000000002 x22: 0001000040000010 x21: 000000007a000000\n[   60.241703] x20: 0000000000200000 x19: 0000000000000000 x18: 0000000000000000\n[   60.248840] x17: 0000000000000000 x16: 0000000000000000 x15: ffff0006ff7b9180\n[   60.255977] x14: ffff0006ff7b9180 x13: 0000000000000000 x12: 0000000000000000\n[   60.263113] x11: 0000000000000000 x10: 0000000000000000 x9 : 0000000000000000\n[   60.270249] x8 : 0001000000000010 x7 : ffff0004c6754b20 x6 : 0000000000000000\n[   60.277385] x5 : ffff0004c0da2090 x4 : 0000000000000000 x3 : 0000000000000001\n[   60.284521] x2 : 0000000040000000 x1 : 0000000000000000 x0 : 0000000040000010\n[   60.291658] Call trace:\n[   60.294100]  swiotlb_tbl_map_single+0x2c0/0x590\n[   60.298629]  swiotlb_map+0x88/0x1f0\n[   60.302115]  dma_map_page_attrs+0x188/0x230\n[   60.306299]  pci_endpoint_test_ioctl+0x5e4/0xd90 [pci_endpoint_test]\n[   60.312660]  __arm64_sys_ioctl+0xa8/0xf0\n[   60.316583]  invoke_syscall+0x44/0x108\n[   60.320334]  el0_svc_common.constprop.0+0xcc/0xf0\n[   60.325038]  do_el0_svc+0x2c/0xb8\n[   60.328351]  el0_svc+0x2c/0x88\n[   60.331406]  el0t_64_sync_handler+0xb8/0xc0\n[   60.335587]  el0t_64_sync+0x18c/0x190\n[   60.339251] Code: 52800013 d2e00414 35fff45c d503201f (d4210000)\n[   60.345344] ---[ end trace 0000000000000000 ]---\n\nTo fix it, this patch adds a checking the payload length if it is zero."
    }
  ],
  "lastModified": "2026-06-17T05:23:52.220",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}