CVE-2022-50132

Source
https://cve.org/CVERecord?id=CVE-2022-50132
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-50132.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2022-50132
Downstream
Related
Published
2025-06-18T11:02:57.498Z
Modified
2026-04-03T13:14:43.498130339Z
Summary
usb: cdns3: change place of 'priv_ep' assignment in cdns3_gadget_ep_dequeue(), cdns3_gadget_ep_enable()
Details

In the Linux kernel, the following vulnerability has been resolved:

usb: cdns3: change place of 'privep' assignment in cdns3gadgetepdequeue(), cdns3gadgetep_enable()

If 'ep' is NULL, result of eptocdns3ep(ep) is invalid pointer and its dereference with privep->cdns3_dev may cause panic.

Found by Linux Verification Center (linuxtesting.org) with SVACE.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/50xxx/CVE-2022-50132.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
7733f6c32e36ff9d7adadf40001039bf219b1cbe
Fixed
7af83bb516d7aa4f96835288e4aeda21d7aa2a17
Fixed
bfa0201468587072454dba7933e4a4a7be44467a
Fixed
d342203df9f2d0851b4acd9ed577d73d10eade77
Fixed
eb82c0382285ee17a9966aaab27b8becb08eb1ac
Fixed
c3ffc9c4ca44bfe9562166793d133e1fb0630ea6

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-50132.json"