Review reviewHigh

CVE-2022-50656

Linux

In the Linux kernel, the following vulnerability has been resolved: nfc: pn533: Clear nfc_target before being used Fix a slab-out-of-bounds read that occurs in nla_put() called from nfc_genl_send_target() when target->sensb_res_len, which is duplicated from an nfc_target in pn533, is too large as the nfc_target is not properly initialized and retains garbage values. Clear nfc_targets with memset() before they are used. Found by a modified version of syzkaller. BUG: KASAN: slab-out-of-bounds in nla_put Call Trace: memcpy nla_put nfc_genl_dump_targets genl_lock_dumpit netlink_dump __netlink_d...

CVSS
8.1
EPSS
0.30%
22.2% percentile
CISA KEV
Not listed
Published
2025.12.09
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.30%
Technical severityCVSS 8.1

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: nfc: pn533: Clear nfc_target before being used Fix a slab-out-of-bounds read that occurs in nla_put() called from nfc_genl_send_target() when target->sensb_res_len, which is duplicated from an nfc_target in pn533, is too large as the nfc_target is not properly initialized and retains garbage values. Clear nfc_targets with memset() before they are used. Found by a modified version of syzkaller. BUG: KASAN: slab-out-of-bounds in nla_put Call Trace: memcpy nla_put nfc_genl_dump_targets genl_lock_dumpit netlink_dump __netlink_d...

Affected product and versions

Product
Linux
Affected versions
>= 361f3cb7f9cfdb82c80926d0e7843c098c034545 < 9da4a0411f3455e3885831d0758bee3e3d565bbc, >= 361f3cb7f9cfdb82c80926d0e7843c098c034545 < 61a7e15d55fae329a245535c3bac494e401005b8, >= 361f3cb7f9cfdb82c80926d0e7843c098c034545 < bef2f478513e7367ef3b05441f6afca981de29be, >= 361f3cb7f9cfdb82c80926d0e7843c098c034545 < 8bddef54cbe9ede5ac7478f1e1e968fcfe7e6f03, >= 361f3cb7f9cfdb82c80926d0e7843c098c034545 < aea9e64dec2cc6cd742e07ecd4e6236fc76b389b, >= 361f3cb7f9cfdb82c80926d0e7843c098c034545 < aae9c24ebd901f482e6c88b6f9e0c80dc5b536d6, >= 361f3cb7f9cfdb82c80926d0e7843c098c034545 < 755019e37815a66bb0a23893debbd3dd640ccbd3, >= 361f3cb7f9cfdb82c80926d0e7843c098c034545 < e491285b4d08884b622638be8e4961eb43b0af64, >= 361f3cb7f9cfdb82c80926d0e7843c098c034545 < 9f28157778ede0d4f183f7ab3b46995bb400abbe, >= 3.3
Fixed versions
No verified fixed-version field is available yet

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
CWE
Not available
CVE-2022-50656 — Linux | SECUFOCUS NOW