Security readout for executives and security teams
Plain-English summary
This is a Linux kernel display-driver flaw in the Qualcomm MSM MDP5 DRM path. The public record shows a locking bug caught by kernel CI, not a described remote compromise path. Business urgency depends on whether affected Linux builds run this display stack, especially on Qualcomm-based systems.
Executive priority
Handle through normal kernel patch governance unless inventory shows affected Qualcomm/MSM display deployments. There is insufficient evidence for emergency response, but kernel fixes should not be deferred indefinitely where the driver is present.
Technical view
The mdp5 global state path could return success after lock contention without actually taking the required modeset lock in a !hwpipe case. CONFIG_DRM_DEBUG_MODESET_LOCK flagged the issue during CI. The sources provide stable kernel commits but no CVSS, CWE, exploit description, or impact statement beyond the locking failure.
Likely exposure
Exposure appears most relevant to Linux systems using the drm/msm/mdp5 display driver, with the trace showing Qualcomm DB820c hardware. General Linux servers without this driver or hardware path are less likely to be exposed, but version and configuration checks are required.
Exploitation context
The source bundle does not show active exploitation, public exploit code, KEV listing, or a weaponized path. It documents a kernel CI warning and a resolved lock-backoff issue. Treat exploitation likelihood as unproven from the provided evidence.
Researcher notes
Evidence is narrow: the record describes a missed lock acquisition/backoff condition in mdp5 and includes stable commit references. Impact, reachability, privilege requirements, and exploitability are not defined in the supplied sources, so risk scoring remains uncertain.
Mitigation direction
Check vendor kernel advisories for CVE-2022-50173 applicability.
Update affected Linux kernels to builds carrying the referenced stable commits.
Prioritize Qualcomm/MSM display systems and embedded Linux images for review.
Track downstream distro or device-vendor kernel backports before deployment.
Validation and detection
Inventory kernel versions against the affected version list.
Confirm whether drm/msm/mdp5 is built or loaded.
Verify the relevant stable commit is present in kernel source or package changelog.
Review kernel logs for related DRM modeset lock warnings.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2022-50173 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
0CVSS vectors
3Timeline events
0ADP providers
8Source links
Vulnerability timeline
Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.
CVE reservedCVE Program
The CVE ID was reserved by the assigning CNA.
CVE publishedCVE Program
The CVE record was published.
Jun 18, 2025, 11:03 UTC (UTC+00:00)
CVE updatedCVE Program
The CVE record metadata indicates this as the latest update time.