CVE-2022-50040: Linux Kernel

High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: net: dsa: sja1105: fix buffer overflow in sja1105_setup_devlink_regions() If an error occurs in dsa_devlink_region_create(), then 'priv->regions' array will be accessed by negative index '-1'. Found by Linux Verification Center (linuxtesting.org) with SVACE.

Affected products

  • Linux Linux Kernel: from 5.10, before 5.10.138 (fixed in 5.10.138); from 5.11, before 5.15.63 (fixed in 5.15.63); from 5.16, before 5.19.4 (fixed in 5.19.4); version 6.0 only

Published 2025-06-18. Last modified 2026-06-17.