CVE-2022-50383: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: media: mediatek: vcodec: Can't set dst buffer to done when lat decode error Core thread will call v4l2_m2m_buf_done to set dst buffer done for lat architecture. If lat call v4l2_m2m_buf_done_and_job_finish to free dst buffer when lat decode error, core thread will access kernel NULL pointer dereference, then crash.

Affected products

  • Linux Linux Kernel: from 5.16, before 6.0.16 (fixed in 6.0.16); from 6.1, before 6.1.2 (fixed in 6.1.2)

Published 2025-09-18. Last modified 2026-06-17.