CVE-2022-50132: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: usb: cdns3: change place of 'priv_ep' assignment in cdns3_gadget_ep_dequeue(), cdns3_gadget_ep_enable() If 'ep' is NULL, result of ep_to_cdns3_ep(ep) is invalid pointer and its dereference with priv_ep->cdns3_dev may cause panic. Found by Linux Verification Center (linuxtesting.org) with SVACE.

Affected products

  • Linux Linux Kernel: from 5.4, before 5.10.137 (fixed in 5.10.137); from 5.11, before 5.15.61 (fixed in 5.15.61); from 5.16, before 5.18.18 (fixed in 5.18.18); from 5.19, before 5.19.2 (fixed in 5.19.2)

Published 2025-06-18. Last modified 2026-06-17.