CVE-2022-50383

Source
https://cve.org/CVERecord?id=CVE-2022-50383
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-50383.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-50383
Downstream
Published
2025-09-18T13:33:04.969Z
Modified
2026-04-02T08:28:27.789953Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
media: mediatek: vcodec: Can't set dst buffer to done when lat decode error
Details

In the Linux kernel, the following vulnerability has been resolved:

media: mediatek: vcodec: Can't set dst buffer to done when lat decode error

Core thread will call v4l2m2mbufdone to set dst buffer done for lat architecture. If lat call v4l2m2mbufdoneandjob_finish to free dst buffer when lat decode error, core thread will access kernel NULL pointer dereference, then crash.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/50xxx/CVE-2022-50383.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
7b182b8d9c852343fb34923a2d1b4e61421b37c7
Fixed
eeb090420f3477eb5011586709409fc655c2b16c
Fixed
66d26ed30056e7d2da3e9c14125ffe6049a4f907
Fixed
3568ecd3f3a6d133ab7feffbba34955c8c79bbc4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-50383.json"