cbcvebase.
CVE-2022-49686
published 2025-02-26

CVE-2022-49686: In the Linux kernel, the following vulnerability has been resolved: usb: gadget: uvc: fix list double add in uvcg_video_pump A panic can occur if the endpoint…

PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.24%
15.8th percentile
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: uvc: fix list double add in uvcg_video_pump A panic can occur if the endpoint becomes disabled and the uvcg_video_pump adds the request back to the req_free list after it has already been queued to the endpoint. The endpoint complete will add the request back to the req_free list. Invalidate the local request handle once it's been queued. [ 246.796704][T13726] configfs-gadget gadget: uvc: uvc_function_set_alt(1, 0) [ 246.797078][ T26] list_add double add: new=ffffff878bee5c40, prev=ffffff878bee5c40, next=ffffff878b0f0a90. [ 246.797213][ T26] ------------[ cut here ]------------ [ 246.797224][ T26] kernel BUG at lib/list_debug.c:31! [ 246.807073][ T26] Call trace: [ 246.807180][ T26] uvcg_video_pump+0x364/0x38c [ 246.807366][ T26] process_one_work+0x2a4/0x544 [ 246.807394][ T26] worker_thread+0x350/0x784 [ 246.807442][ T26] kthread+0x2ac/0x320

Affected

9 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.18.14-1 (bookworm)linux 5.18.14-1 (bookworm)
linuxlinux
linuxlinux>= f9897ec0f6d34e8b2bc2f4c8ab8789351090f3d2 < d95ac8b920de1d39525fadc408ce675697626ca6d95ac8b920de1d39525fadc408ce675697626ca6
linuxlinux>= f9897ec0f6d34e8b2bc2f4c8ab8789351090f3d2 < 96163f835e65f8c9897487fac965819f0651d67196163f835e65f8c9897487fac965819f0651d671
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 0 < 5.18.14-15.18.14-1
linuxlinux_kernel>= 5.16 < 5.18.85.18.8

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.