Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2022-50656

8.1 · HIGH
Published Dec 9, 2025 EPSS 0.34% (27th pctl)

Overview

CVE-2022-50656 is a high-severity vulnerability. It was published on December 9, 2025 and has a CVSS 3.1 base score of 8.1 (HIGH).

This vulnerability has a CVSS 3.1 base score of 8.1, rated HIGH. It requires local or adjacent network access to exploit. No authentication or special privileges are required for exploitation.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

nfc: pn533: Clear nfc_target before being used

Fix a slab-out-of-bounds read that occurs in nla_put() called from

nfc_genl_send_target() when target->sensb_res_len, which is duplicated

from an nfc_target in pn533, is too large as the nfc_target is not

properly initialized and retains garbage values. Clear nfc_targets with

memset() before they are used.

Found by a modified version of syzkaller.

BUG: KASAN: slab-out-of-bounds in nla_put

Call Trace:

memcpy

nla_put

nfc_genl_dump_targets

genl_lock_dumpit

netlink_dump

__netlink_dump_start

genl_family_rcv_msg_dumpit

genl_rcv_msg

netlink_rcv_skb

genl_rcv

netlink_unicast

netlink_sendmsg

sock_sendmsg

____sys_sendmsg

___sys_sendmsg

__sys_sendmsg

do_syscall_64

Remediation

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Frequently Asked Questions

What is CVE-2022-50656?

CVE-2022-50656 is a high-severity vulnerability. It was published on December 9, 2025 and has a CVSS 3.1 base score of 8.1 (HIGH).

How severe is CVE-2022-50656?

This vulnerability has a CVSS 3.1 base score of 8.1, rated HIGH. It requires local or adjacent network access to exploit. No authentication or special privileges are required for exploitation.

How do I fix or remediate CVE-2022-50656?

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2022-50656?

CyberStrike's AI-powered security agents can automatically detect CVE-2022-50656 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.