CVE-2022-50096

MEDIUM

Linux Kernel 5.13-5.15.60, 5.16-5.18.17, 5.19.0-5.19.1 - Denial of Service via Kprobes INT3 Handler

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: x86/kprobes: Update kcb status flag after singlestepping Fix kprobes to update kcb (kprobes control block) status flag to KPROBE_HIT_SSDONE even if the kp->post_handler is not set. This bug may cause a kernel panic if another INT3 user runs right after kprobes because kprobe_int3_handler() misunderstands the INT3 is kprobe's single stepping INT3.

Scores

CVSS v3 5.5
EPSS 0.0020
EPSS Percentile 10.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

Status published
Products (15)
linux/Kernel 5.13.0 - 5.15.61linux
linux/Kernel 5.16.0 - 5.18.18linux
linux/Kernel 5.19.0 - 5.19.2linux
Linux/Linux < 5.13
Linux/Linux 5.13
Linux/Linux 5.15.61 - 5.15.*
Linux/Linux 5.18.18 - 5.18.*
Linux/Linux 5.19.2 - 5.19.*
Linux/Linux 6.0
Linux/Linux 6256e668b7af9d81472e03c6a171630c08f8858a - 1cbf3882cb372bbe752efd7c3045ca1c9ab40ac6
... and 5 more
Published Jun 18, 2025
Tracked Since Feb 18, 2026