CVE-2022-50256Use After Free in Linux

CWE-416Use After Free10 documents6 sources
Severity
7.8HIGHNVD
EPSS
0.0%
top 97.35%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 15

Description

In the Linux kernel, the following vulnerability has been resolved: drm/meson: remove drm bridges at aggregate driver unbind time drm bridges added by meson_encoder_hdmi_init and meson_encoder_cvbs_init were not manually removed at module unload time, which caused dangling references to freed memory to remain linked in the global bridge_list. When loading the driver modules back in, the same functions would again call drm_bridge_add, and when traversing the global bridge_list, would end up pe

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages7 packages

NVDlinux/linux_kernel4.105.19.17+1
Debianlinux/linux_kernel< 6.0.3-1+2
CVEListV5linux/linuxbbbe775ec5b5dace43a35886da9924837da09dddde2b6ebe0cb7746b5b6b35d79e150d934392b958+3
debiandebian/linux< linux 6.0.3-1 (bookworm)

Patches

🔴Vulnerability Details

6
OSV
CVE-2022-50256: In the Linux kernel, the following vulnerability has been resolved: drm/meson: remove drm bridges at aggregate driver unbind time drm bridges added by2025-09-15
GHSA
GHSA-qh76-9567-4h37: In the Linux kernel, the following vulnerability has been resolved: drm/meson: remove drm bridges at aggregate driver unbind time drm bridges added2025-09-15
OSV
linux-aws-5.15 vulnerabilities2025-04-29
OSV
linux-oracle-5.15 vulnerabilities2025-04-25
OSV
linux-intel-iot-realtime, linux-realtime vulnerabilities2025-04-24

📋Vendor Advisories

3
Red Hat
kernel: drm/meson: remove drm bridges at aggregate driver unbind time2025-09-15
Microsoft
drm/meson: remove drm bridges at aggregate driver unbind time2025-09-09
Debian
CVE-2022-50256: linux - In the Linux kernel, the following vulnerability has been resolved: drm/meson: ...2022
CVE-2022-50256 — Use After Free in Linux | cvebase