CVE-2022-50080 Details
Description
In the Linux kernel, the following vulnerability has been resolved: tee: add overflow check in register_shm_helper() With special lengths supplied by user space, register_shm_helper() has an integer overflow when calculating the number of pages covered by a supplied user space memory region. This causes internal_get_user_pages_fast() a helper function of pin_user_pages_fast() to do a NULL pointer dereference: Unable to handle kernel NULL pointer dereference at virtual address 0000000000000010 Modules linked in: CPU: 1 PID: 173 Comm: optee_example_a Not tainted 5.19.0 #11 Hardware name: QEMU QEMU Virtual Machine, BIOS 0.0.0 02/06/2015 pc : internal_get_user_pages_fast+0x474/0xa80 Call trace: internal_get_user_pages_fast+0x474/0xa80 pin_user_pages_fast+0x24/0x4c register_shm_helper+0x194/0x330 tee_shm_register_user_buf+0x78/0x120 tee_ioctl+0xd0/0x11a0 __arm64_sys_ioctl+0xa8/0xec invoke_syscall+0x48/0x114 Fix this by adding an an explicit call to access_ok() in tee_shm_register_user_buf() to catch an invalid user space address early.
A vulnerability in the Linux kernel's TEE (Trusted Execution Environment) subsystem has been identified, specifically in the 'tee_shm_register_user_buf()' function. This issue arises from 'register_shm_helper()''s' improper handling of user-supplied memory lengths, leading to an integer overflow. The overflow allows 'internal_get_user_pages_fast()', a helper for 'pin_user_pages_fast()', to dereference a NULL pointer, causing a kernel crash. The vulnerability has been addressed by adding a check for valid user space addresses before processing the memory region.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/2f8e79a1a6128214cb9b205a9869341af5dfb16b | kernel.org | Patch |
| https://git.kernel.org/stable/c/573ae4f13f630d6660008f1974c0a8a29c30e18a | kernel.org | Patch |
| https://git.kernel.org/stable/c/578c349570d2a912401963783b36e0ec7a25c053 | kernel.org | Patch |
| https://git.kernel.org/stable/c/58c008d4d398f792ca67f35650610864725518fd | kernel.org | Patch |
| https://git.kernel.org/stable/c/965333345fe952cc7eebc8e3a565ffc709441af2 | kernel.org | Patch |
| https://git.kernel.org/stable/c/b37e0f17653c00b586cdbcdf0dbca475358ecffd | kernel.org | Patch |
| https://git.kernel.org/stable/c/c12f0e6126ad223806a365084e86370511654bf1 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-476 | NULL Pointer Dereference | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 4.16, < 4.19.256 >= 4.20, < 5.4.211 >= 5.5, < 5.10.137 >= 5.11, < 5.15.62 >= 5.16, < 5.18.19 >= 5.19, < 5.19.3 6.0 rc1 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| Nov 18, 2025 | Initial Analysis | [email protected] |
| Jun 18, 2025 | New CVE Received | kernel.org |