CVE-2022-50222: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: tty: vt: initialize unicode screen buffer syzbot reports kernel infoleak at vcs_read() [1], for buffer can be read immediately after resize operation. Initialize buffer using kzalloc(). ---------- #include <fcntl.h> #include <unistd.h> #include <sys/ioctl.h> #include <linux/fb.h> int main(int argc, char *argv[]) { struct fb_var_screeninfo var = { }; const int fb_fd = open("/dev/fb0", 3); ioctl(fb_fd, FBIOGET_VSCREENINFO, &var); var.yres = 0x21; ioctl(fb_fd, FBIOPUT_VSCREENINFO, &var); return read(open("/dev/vcsu", O_RDONLY), &var, sizeof(var)) == -1; } ----------

Affected products

  • Linux Linux Kernel: from 4.19, before 4.19.256 (fixed in 4.19.256); from 4.20, before 5.4.211 (fixed in 5.4.211); from 5.5, before 5.10.137 (fixed in 5.10.137); from 5.11, before 5.15.61 (fixed in 5.15.61); from 5.16, before 5.18.18 (fixed in 5.18.18); from 5.19, before 5.19.2 (fixed in 5.19.2)

Published 2025-06-18. Last modified 2026-06-17.