Answer in brief
CVE-2022-50421 records a Unknown severity vulnerability in rpmsg: char: Avoid double destroy of default endpoint. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=bea9b79c2d10fecf7bfa26e212ecefe61d232e39 <ef828a39d6a7028836eaf37df3ad568c8c2dd6f9 || >=bea9b79c2d10fecf7bfa26e212ecefe61d232e39 <3f20ef7a845c2c8d7ec82ecffa20d95cab5ecfeb || >=bea9b79c2d10fecf7bfa26e212ecefe61d232e39 <467233a4ac29b215d492843d067a9f091e6bf0c5 | ef828a39d6a7028836eaf37df3ad568c8c2dd6f9, 3f20ef7a845c2c8d7ec82ecffa20d95cab5ecfeb, 467233a4ac29b215d492843d067a9f091e6bf0c5 |
| Linux/Linuxgeneric | 5.18 | Not reported |
Published upstream
Oct 1, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: rpmsg: char: Avoid double destroy of default endpoint The rpmsg_dev_remove() in rpmsg_core is the place for releasing this default endpoint. So need to avoid destroying the default endpoint in rpmsg_chrdev_eptdev_destroy(), this should be the same as rpmsg_eptdev_release(). Otherwise there will be double destroy issue that ept->refcount report warning: refcount_t: underflow; use-after-free. Call trace: refcount_warn_saturate+0xf8/0x150 virtio_rpmsg_destroy_ept+0xd4/0xec rpmsg_dev_remove+0x60/0x70 The issue can be reproduced by stopping remoteproc before closing the /dev/rpmsgX.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2022-50421 records a Unknown severity vulnerability in rpmsg: char: Avoid double destroy of default endpoint. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=bea9b79c2d10fecf7bfa26e212ecefe61d232e39 <ef828a39d6a7028836eaf37df3ad568c8c2dd6f9 || >=bea9b79c2d10fecf7bfa26e212ecefe61d232e39 <3f20ef7a845c2c8d7ec82ecffa20d95cab5ecfeb || >=bea9b79c2d10fecf7bfa26e212ecefe61d232e39 <467233a4ac29b215d492843d067a9f091e6bf0c5 | ef828a39d6a7028836eaf37df3ad568c8c2dd6f9, 3f20ef7a845c2c8d7ec82ecffa20d95cab5ecfeb, 467233a4ac29b215d492843d067a9f091e6bf0c5 |
| Linux/Linuxgeneric | 5.18 | Not reported |
Published upstream
Oct 1, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: rpmsg: char: Avoid double destroy of default endpoint The rpmsg_dev_remove() in rpmsg_core is the place for releasing this default endpoint. So need to avoid destroying the default endpoint in rpmsg_chrdev_eptdev_destroy(), this should be the same as rpmsg_eptdev_release(). Otherwise there will be double destroy issue that ept->refcount report warning: refcount_t: underflow; use-after-free. Call trace: refcount_warn_saturate+0xf8/0x150 virtio_rpmsg_destroy_ept+0xd4/0xec rpmsg_dev_remove+0x60/0x70 The issue can be reproduced by stopping remoteproc before closing the /dev/rpmsgX.
Quoted source text, attributed separately from HOL analysis.