CVE-2022-41849 — Race Condition in Linux
Severity
4.2MEDIUMNVD
OSV6.7OSV6.6OSV5.9OSV5.5
EPSS
0.0%
top 94.17%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 30
Latest updateJun 15
Description
drivers/video/fbdev/smscufx.c in the Linux kernel through 5.19.12 has a race condition and resultant use-after-free if a physically proximate attacker removes a USB device while calling open(), aka a race condition between ufx_ops_open and ufx_usb_disconnect.
CVSS vector
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 0.5 | Impact: 3.6
Affected Packages10 packages
Also affects: Debian Linux 10.0