CVE-2022-50817: net: hsr: avoid possible NULL deref in skb_clone()

Published Dec 30, 2025
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

net: hsr: avoid possible NULL deref in skbclone()

syzbot got a crash [1] in skbclone(), caused by a bug in hsrgetuntaggedframe().

When/if createstrippedskbhsr() returns NULL, we must not attempt to call skbclone().

While we are at it, replace a WARNONCE() by netdevwarnonce().

[1] general protection fault, probably for non-canonical address 0xdffffc000000000f: 0000 [#1] PREEMPT SMP KASAN KASAN: null-ptr-deref in range [0x0000000000000078-0x000000000000007f] CPU: 1 PID: 754 Comm: syz-executor.0 Not tainted 6.0.0-syzkaller-02734-g0326074ff465 #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/22/2022 RIP: 0010:skbclone+0x108/0x3c0 net/core/skbuff.c:1641 Code: 93 02 00 00 49 83 7c 24 28 00 0f 85 e9 00 00 00 e8 5d 4a 29 fa 4c 8d 75 7e 48 b8 00 00 00 00 00 fc ff df 4c 89 f2 48 c1 ea 03 <0f> b6 04 02 4c 89 f2 83 e2 07 38 d0 7f 08 84 c0 0f 85 9e 01 00 00 RSP: 0018:ffffc90003ccf4e0 EFLAGS: 00010207

RAX: dffffc0000000000 RBX: ffffc90003ccf5f8 RCX: ffffc9000c24b000 RDX: 000000000000000f RSI: ffffffff8751cb13 RDI: 0000000000000000 RBP: 0000000000000000 R08: 00000000000000f0 R09: 0000000000000140 R10: fffffbfff181d972 R11: 0000000000000000 R12: ffff888161fc3640 R13: 0000000000000a20 R14: 000000000000007e R15: ffffffff8dc5f620 FS: 00007feb621e4700(0000) GS:ffff8880b9b00000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007feb621e3ff8 CR3: 00000001643a9000 CR4: 00000000003506e0 DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 Call Trace: <TASK> hsrgetuntaggedframe+0x4e/0x610 net/hsr/hsrforward.c:164 hsrforwarddo net/hsr/hsrforward.c:461 [inline] hsrforwardskb+0xcca/0x1d50 net/hsr/hsrforward.c:623 hsrhandleframe+0x588/0x7c0 net/hsr/hsrslave.c:69 netifreceiveskbcore+0x9fe/0x38f0 net/core/dev.c:5379 netifreceiveskbonecore+0xae/0x180 net/core/dev.c:5483 netifreceiveskb+0x1f/0x1c0 net/core/dev.c:5599 netifreceiveskbinternal net/core/dev.c:5685 [inline] netifreceiveskb+0x12f/0x8d0 net/core/dev.c:5744 tunrxbatched+0x4ab/0x7a0 drivers/net/tun.c:1544 tungetuser+0x2686/0x3a00 drivers/net/tun.c:1995 tunchrwriteiter+0xdb/0x200 drivers/net/tun.c:2025 callwriteiter include/linux/fs.h:2187 [inline] newsyncwrite fs/readwrite.c:491 [inline] vfswrite+0x9e9/0xdd0 fs/readwrite.c:584 ksyswrite+0x127/0x250 fs/readwrite.c:637 dosyscallx64 arch/x86/entry/common.c:50 [inline] dosyscall64+0x35/0xb0 arch/x86/entry/common.c:80 entrySYSCALL64afterhwframe+0x63/0xcd

Affected Software

1 affected component
Linux Foundation Linux Kernel

Event History

Dec 30, 2025
CVE Published
via MITRE·12:08 PM
Data Sourced
via MITRE·12:08 PM
Description
Data Sourced
via NVD·01:15 PM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2022-50817?

CVE-2022-50817 has been assessed for impact, with details usually available in security reports.

2

How do I fix CVE-2022-50817?

To mitigate CVE-2022-50817, update the Linux kernel to the latest patched version that addresses this vulnerability.

3

What impact does CVE-2022-50817 have on Linux systems?

CVE-2022-50817 could lead to a possible NULL dereference, which may cause system crashes under specific conditions.

4

Which versions of the Linux kernel are affected by CVE-2022-50817?

CVE-2022-50817 affects various versions of the Linux kernel; consult release notes for details on impacted versions.

5

Who reported CVE-2022-50817?

CVE-2022-50817 was reported through the syzbot testing framework, highlighting an issue in the kernel's networking code.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203