CVE-2022-50452: net: sched: cake: fix null pointer access issue when cake_init() fails

Published Oct 1, 2025
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

net: sched: cake: fix null pointer access issue when cakeinit() fails

When the default qdisc is cake, if the qdisc of devqueue fails to be inited during mqprioinit(), cakereset() is invoked to clear resources. In this case, the tins is NULL, and it will cause gpf issue.

The process is as follows: qdisccreatedflt() cakeinit() q->tins = kvcalloc(...) --->failed, q->tins is NULL ... qdiscput() ... cakereset() ... cakedequeueone() b = &q->tins[...] --->q->tins is NULL

The following is the Call Trace information: general protection fault, probably for non-canonical address 0xdffffc0000000000: 0000 [#1] PREEMPT SMP KASAN KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007] RIP: 0010:cakedequeueone+0xc9/0x3c0 Call Trace: <TASK> cakereset+0xb1/0x140 qdiscreset+0xed/0x6f0 qdiscdestroy+0x82/0x4c0 qdiscput+0x9e/0xb0 qdisccreatedflt+0x2c3/0x4a0 mqprioinit+0xa71/0x1760 qdisccreate+0x3eb/0x1000 tcmodifyqdisc+0x408/0x1720 rtnetlinkrcvmsg+0x38e/0xac0 netlinkrcvskb+0x12d/0x3a0 netlinkunicast+0x4a2/0x740 netlinksendmsg+0x826/0xcc0 socksendmsg+0xc5/0x100 syssendmsg+0x583/0x690 syssendmsg+0xe8/0x160 syssendmsg+0xbf/0x160 dosyscall64+0x35/0x80 entrySYSCALL64afterhwframe+0x46/0xb0 RIP: 0033:0x7f89e5122d04 </TASK>

Affected Software

7 affected components
Linux Kernel
Linux Linux kernel>=4.19<4.19.264
Linux Linux kernel>=4.20<5.4.221
Linux Linux kernel>=5.5<5.10.152
Linux Linux kernel>=5.11<5.15.76
Linux Linux kernel>=5.16<6.0.6
Linux Linux kernel=6.1-rc1

Event History

Oct 1, 2025
CVE Published
via MITRE·11:45 AM
Data Sourced
via MITRE·11:45 AM
Description
Data Sourced
via NVD·12:15 PM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2022-50452?

CVE-2022-50452 has a medium severity rating due to the potential for a null pointer dereference issue in the Linux kernel.

2

How do I fix CVE-2022-50452?

To fix CVE-2022-50452, update your Linux kernel to the latest patched version that addresses this vulnerability.

3

Which versions of the Linux kernel are affected by CVE-2022-50452?

CVE-2022-50452 affects certain versions of the Linux kernel where the cake packet scheduler is used.

4

What components are impacted by CVE-2022-50452?

CVE-2022-50452 specifically impacts the net subsystem of the Linux kernel, particularly the cake scheduler implementation.

5

Is CVE-2022-50452 exploitable remotely?

CVE-2022-50452 is not typically considered remotely exploitable, as it requires specific conditions within the affected system.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203