LiveActive security incident?Get immediate response
CVE Record

CVE-2022-50651: ethtool: eeprom: fix null-deref on genl_info in dump

In the Linux kernel, the following vulnerability has been resolved: ethtool: eeprom: fix null-deref on genl_info in dump The similar fix as commit 46cdedf2a0fa ("ethtool: pse-pd: fix null-deref on genl_info in dump") is also needed for ethtool eeprom.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

CVE-2022-50651 is a Linux kernel null-pointer dereference in the ethtool EEPROM dump path. In practical terms, this is most likely an availability concern, such as a kernel crash, if the affected code path is reachable. The public bundle does not provide CVSS, privilege requirements, or evidence of active exploitation.

Executive priority

Treat this as a normal kernel maintenance priority unless vendor guidance raises severity. There is no sourced evidence of active exploitation, but kernel availability bugs can disrupt business services when reachable. Confirm affected assets and apply vendor-supported kernel updates.

Technical view

The Linux kernel ethtool EEPROM generic netlink dump handler could dereference a null genl_info pointer. The CVE states this was resolved with a fix similar to an earlier ethtool pse-pd null-dereference fix. Stable kernel commit references are provided, but the bundle does not fully clarify affected range semantics.

Likely exposure

Exposure is limited to systems running affected Linux kernel builds with the vulnerable ethtool EEPROM code. The source bundle lists Linux kernel versions and stable commits, but exact downstream distribution package status must be confirmed with each vendor.

Exploitation context

No CISA KEV entry is indicated, and the provided sources do not claim active exploitation. The sources also do not define whether exploitation is local, remote, privileged, or unprivileged, so operational exposure should be validated through kernel and vendor advisories.

Researcher notes

The public record is sparse: no CVSS, CWE, privilege model, or proof-of-concept details are included. The key artifacts are the CVE description and three kernel stable commits. Further analysis should focus on commit diffs, backport status, and downstream vendor package mapping.

Mitigation direction

  • Identify Linux systems and appliances using affected kernel branches.
  • Check distribution and appliance vendor advisories for CVE-2022-50651 status.
  • Update to a vendor kernel that includes the referenced stable fixes.
  • Prioritize internet-facing or high-availability systems after vendor impact confirmation.

Validation and detection

  • Inventory running kernel versions across servers, containers hosts, and appliances.
  • Compare installed kernel packages against vendor CVE advisories.
  • Review kernel changelogs for the referenced ethtool EEPROM null-deref fix.
  • Monitor systems for kernel oops or panic events involving ethtool EEPROM paths.
Prepared
Confidence
medium
Sources
5

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2022-50651 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
4Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
LinuxLinuxc781ff12a2f37a9795e13bf328e5053d3e69f9e0, c781ff12a2f37a9795e13bf328e5053d3e69f9e0, c781ff12a2f37a9795e13bf328e5053d3e69f9e0unaffected
LinuxLinux5.13, 0, 5.15.77, 6.0.7, 6.1affected
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.