Answer in brief
CVE-2022-50527 records a Unknown severity vulnerability in drm/amdgpu: Fix size validation for non-exclusive domains (v4). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=a751612d4cb77779669da0a6d19fbc4f7e72ba6f <80546eef216854a7bd47e39e828f04b406c00599 || >=a751612d4cb77779669da0a6d19fbc4f7e72ba6f <8ba7c55e112f4ffd2a95b99be1cb1c891ef08ba1 || >=a751612d4cb77779669da0a6d19fbc4f7e72ba6f <7554886daa31eacc8e7fac9e15bbce67d10b8f1f | 80546eef216854a7bd47e39e828f04b406c00599, 8ba7c55e112f4ffd2a95b99be1cb1c891ef08ba1, 7554886daa31eacc8e7fac9e15bbce67d10b8f1f |
| Linux/Linuxgeneric | 5.10 | Not reported |
Published upstream
Oct 7, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix size validation for non-exclusive domains (v4) Fix amdgpu_bo_validate_size() to check whether the TTM domain manager for the requested memory exists, else we get a kernel oops when dereferencing "man". v2: Make the patch standalone, i.e. not dependent on local patches. v3: Preserve old behaviour and just check that the manager pointer is not NULL. v4: Complain if GTT domain requested and it is uninitialized--most likely a bug.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2022-50527 records a Unknown severity vulnerability in drm/amdgpu: Fix size validation for non-exclusive domains (v4). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=a751612d4cb77779669da0a6d19fbc4f7e72ba6f <80546eef216854a7bd47e39e828f04b406c00599 || >=a751612d4cb77779669da0a6d19fbc4f7e72ba6f <8ba7c55e112f4ffd2a95b99be1cb1c891ef08ba1 || >=a751612d4cb77779669da0a6d19fbc4f7e72ba6f <7554886daa31eacc8e7fac9e15bbce67d10b8f1f | 80546eef216854a7bd47e39e828f04b406c00599, 8ba7c55e112f4ffd2a95b99be1cb1c891ef08ba1, 7554886daa31eacc8e7fac9e15bbce67d10b8f1f |
| Linux/Linuxgeneric | 5.10 | Not reported |
Published upstream
Oct 7, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix size validation for non-exclusive domains (v4) Fix amdgpu_bo_validate_size() to check whether the TTM domain manager for the requested memory exists, else we get a kernel oops when dereferencing "man". v2: Make the patch standalone, i.e. not dependent on local patches. v3: Preserve old behaviour and just check that the manager pointer is not NULL. v4: Complain if GTT domain requested and it is uninitialized--most likely a bug.
Quoted source text, attributed separately from HOL analysis.