CVE-2022-49686
published 2025-02-26CVE-2022-49686: In the Linux kernel, the following vulnerability has been resolved: usb: gadget: uvc: fix list double add in uvcg_video_pump A panic can occur if the endpoint…
PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.24%
15.8th percentile
In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: uvc: fix list double add in uvcg_video_pump
A panic can occur if the endpoint becomes disabled and the
uvcg_video_pump adds the request back to the req_free list after it has
already been queued to the endpoint. The endpoint complete will add the
request back to the req_free list. Invalidate the local request handle
once it's been queued.
[ 246.796704][T13726] configfs-gadget gadget: uvc: uvc_function_set_alt(1, 0)
[ 246.797078][ T26] list_add double add: new=ffffff878bee5c40, prev=ffffff878bee5c40, next=ffffff878b0f0a90.
[ 246.797213][ T26] ------------[ cut here ]------------
[ 246.797224][ T26] kernel BUG at lib/list_debug.c:31!
[ 246.807073][ T26] Call trace:
[ 246.807180][ T26] uvcg_video_pump+0x364/0x38c
[ 246.807366][ T26] process_one_work+0x2a4/0x544
[ 246.807394][ T26] worker_thread+0x350/0x784
[ 246.807442][ T26] kthread+0x2ac/0x320
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.18.14-1 (bookworm) | linux 5.18.14-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= f9897ec0f6d34e8b2bc2f4c8ab8789351090f3d2 < d95ac8b920de1d39525fadc408ce675697626ca6 | d95ac8b920de1d39525fadc408ce675697626ca6 |
| linux | linux | >= f9897ec0f6d34e8b2bc2f4c8ab8789351090f3d2 < 96163f835e65f8c9897487fac965819f0651d671 | 96163f835e65f8c9897487fac965819f0651d671 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.18.14-1 | 5.18.14-1 |
| linux | linux_kernel | >= 0 < 5.18.14-1 | 5.18.14-1 |
| linux | linux_kernel | >= 0 < 5.18.14-1 | 5.18.14-1 |
| linux | linux_kernel | >= 5.16 < 5.18.8 | 5.18.8 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-p67w-5h3h-82g5: In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: uvc: fix list double add in uvcg_video_pump
A panic can occur if th
ghsa_unreviewed·2025-10-24
CVE-2022-49686 [HIGH] CWE-415 GHSA-p67w-5h3h-82g5: In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: uvc: fix list double add in uvcg_video_pump
A panic can occur if th
In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: uvc: fix list double add in uvcg_video_pump
A panic can occur if the endpoint becomes disabled and the
uvcg_video_pump adds the request back to the req_free list after it has
already been queued to the endpoint. The endpoint complete will add the
request back to the req_free list. Invalidate the local request handle
once it's been queued.
[ 246.796704][T13726] configfs-gadget gadget: uvc: uvc_function_set_alt(1, 0)
[ 246.797078][ T26] list_add double add: new=ffffff878bee5c40, prev=ffffff878bee5c40, next=ffffff878b0f0a90.
[ 246.797213][ T26] ------------[ cut here ]------------
[ 246.797224][ T26] kernel BUG at lib/list_debug.c:31!
[ 246.807073][ T26] Call trace:
[ 246.807180][ T26] uvcg_video_pump+0x364/0x
OSV
CVE-2022-49686: In the Linux kernel, the following vulnerability has been resolved: usb: gadget: uvc: fix list double add in uvcg_video_pump A panic can occur if the
osv·2025-02-26·CVSS 7.8
CVE-2022-49686 [HIGH] CVE-2022-49686: In the Linux kernel, the following vulnerability has been resolved: usb: gadget: uvc: fix list double add in uvcg_video_pump A panic can occur if the
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: uvc: fix list double add in uvcg_video_pump A panic can occur if the endpoint becomes disabled and the uvcg_video_pump adds the request back to the req_free list after it has already been queued to the endpoint. The endpoint complete will add the request back to the req_free list. Invalidate the local request handle once it's been queued. [ 246.796704][T13726] configfs-gadget gadget: uvc: uvc_function_set_alt(1, 0) [ 246.797078][ T26] list_add double add: new=ffffff878bee5c40, prev=ffffff878bee5c40, next=ffffff878b0f0a90. [ 246.797213][ T26] ------------[ cut here ]------------ [ 246.797224][ T26] kernel BUG at lib/list_debug.c:31! [ 246.807073][ T26] Call trace: [ 246.807180][ T26] uvcg_video_pump+0x364/0x38c
Red Hat
kernel: usb: gadget: uvc: fix list double add in uvcg_video_pump
vendor_redhat·2025-02-26·CVSS 7.8
CVE-2022-49686 [HIGH] kernel: usb: gadget: uvc: fix list double add in uvcg_video_pump
kernel: usb: gadget: uvc: fix list double add in uvcg_video_pump
In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: uvc: fix list double add in uvcg_video_pump
A panic can occur if the endpoint becomes disabled and the
uvcg_video_pump adds the request back to the req_free list after it has
already been queued to the endpoint. The endpoint complete will add the
request back to the req_free list. Invalidate the local request handle
once it's been queued.
[ 246.796704][T13726] configfs-gadget gadget: uvc: uvc_function_set_alt(1, 0)
[ 246.797078][ T26] list_add double add: new=ffffff878bee5c40, prev=ffffff878bee5c40, next=ffffff878b0f0a90.
[ 246.797213][ T26] ------------[ cut here ]------------
[ 246.797224][ T26] kernel BUG at lib/list_debug.c:31!
[ 246.807073]
Debian
CVE-2022-49686: linux - In the Linux kernel, the following vulnerability has been resolved: usb: gadget...
vendor_debian·2022·CVSS 7.8
CVE-2022-49686 [HIGH] CVE-2022-49686: linux - In the Linux kernel, the following vulnerability has been resolved: usb: gadget...
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: uvc: fix list double add in uvcg_video_pump A panic can occur if the endpoint becomes disabled and the uvcg_video_pump adds the request back to the req_free list after it has already been queued to the endpoint. The endpoint complete will add the request back to the req_free list. Invalidate the local request handle once it's been queued. [ 246.796704][T13726] configfs-gadget gadget: uvc: uvc_function_set_alt(1, 0) [ 246.797078][ T26] list_add double add: new=ffffff878bee5c40, prev=ffffff878bee5c40, next=ffffff878b0f0a90. [ 246.797213][ T26] ------------[ cut here ]------------ [ 246.797224][ T26] kernel BUG at lib/list_debug.c:31! [ 246.807073][ T26] Call trace: [ 246.807180][ T26] uvcg_video_pump+0x364/0x38c
No detection rules found.
No public exploits indexed.
2025-02-26
Published