CVE-2022-50656

Source
https://cve.org/CVERecord?id=CVE-2022-50656
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-50656.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2022-50656
Downstream
Related
Published
2025-12-09T00:00:31.691Z
Modified
2026-03-20T11:47:34.244231Z
Summary
nfc: pn533: Clear nfc_target before being used
Details

In the Linux kernel, the following vulnerability has been resolved:

nfc: pn533: Clear nfc_target before being used

Fix a slab-out-of-bounds read that occurs in nlaput() called from nfcgenlsendtarget() when target->sensbreslen, which is duplicated from an nfctarget in pn533, is too large as the nfctarget is not properly initialized and retains garbage values. Clear nfc_targets with memset() before they are used.

Found by a modified version of syzkaller.

BUG: KASAN: slab-out-of-bounds in nlaput Call Trace: memcpy nlaput nfcgenldumptargets genllockdumpit netlinkdump __netlinkdumpstart genlfamilyrcvmsgdumpit genlrcvmsg netlinkrcvskb genlrcv netlinkunicast netlinksendmsg socksendmsg ____sys_sendmsg ___sys_sendmsg _syssendmsg dosyscall64

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/50xxx/CVE-2022-50656.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
361f3cb7f9cfdb82c80926d0e7843c098c034545
Fixed
9da4a0411f3455e3885831d0758bee3e3d565bbc
Fixed
61a7e15d55fae329a245535c3bac494e401005b8
Fixed
bef2f478513e7367ef3b05441f6afca981de29be
Fixed
8bddef54cbe9ede5ac7478f1e1e968fcfe7e6f03
Fixed
aea9e64dec2cc6cd742e07ecd4e6236fc76b389b
Fixed
aae9c24ebd901f482e6c88b6f9e0c80dc5b536d6
Fixed
755019e37815a66bb0a23893debbd3dd640ccbd3
Fixed
e491285b4d08884b622638be8e4961eb43b0af64
Fixed
9f28157778ede0d4f183f7ab3b46995bb400abbe

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-50656.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.3.0
Fixed
4.9.337
Type
ECOSYSTEM
Events
Introduced
4.10.0
Fixed
4.14.303
Type
ECOSYSTEM
Events
Introduced
4.15.0
Fixed
4.19.270
Type
ECOSYSTEM
Events
Introduced
4.20.0
Fixed
5.4.229
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.163
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.86
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.0.16
Type
ECOSYSTEM
Events
Introduced
6.1.0
Fixed
6.1.2

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-50656.json"