Junglewise Threat Intelligence

CVE-2022-50555: Linux kernel TIPC null pointer dereference in tipc_topsrv_accept

CVE-2022-50555 · Severity: high · CVSS 7.8 · Published 2025-10-07

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's TIPC (Transparent Inter-Process Communication) networking subsystem contains a race condition in its topology server that can cause a null pointer dereference, leading to a kernel crash. An attacker with local access could trigger this vulnerability during specific shutdown sequences, disrupting system availability or potentially escalating privileges through kernel memory manipulation.

Technical details

This is a use-after-free / race condition vulnerability in net/tipc/topsrv.c. The tipc_topsrv_accept() worker thread reads the srv->listener socket pointer without proper synchronization, while tipc_topsrv_stop() (called during network namespace exit) nullifies this pointer. When tipc_topsrv_accept() executes concurrently with tipc_topsrv_stop(), it can dereference a null listener socket, causing a kernel panic detected by KASAN. The fix adds spinlock protection (srv->idr_lock) to check srv->listener validity in tipc_topsrv_accept() before use, and reorders cleanup in tipc_topsrv_stop() to ensure the worker completes before socket release. Local network namespace manipulation or crafted TIPC packets can trigger this race.

Affected products

  • Linux Linux Kernel Affected versions include Linux 4.14 through 5.x; patched in stable releases via commit 82cb4e4612c633a9ce320e1773114875604a3cce

Timeline

  • 2022-10-18: disclosed: Vulnerability reported by syzbot
  • 2022-10-18: patched: Fix committed upstream
  • 2025-10-07: advisory

References

Related threats