CVE-2022-50384
published 2025-09-18CVE-2022-50384: In the Linux kernel, the following vulnerability has been resolved: staging: vme_user: Fix possible UAF in tsi148_dma_list_add Smatch report warning as…
PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.16%
5.3th percentile
In the Linux kernel, the following vulnerability has been resolved:
staging: vme_user: Fix possible UAF in tsi148_dma_list_add
Smatch report warning as follows:
drivers/staging/vme_user/vme_tsi148.c:1757 tsi148_dma_list_add() warn:
'&entry->list' not removed from list
In tsi148_dma_list_add(), the error path "goto err_dma" will not
remove entry->list from list->entries, but entry will be freed,
then list traversal may cause UAF.
Fix by removeing it from list->entries before free().
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.4-1 (bookworm) | linux 6.1.4-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= b2383c90a9d691201b9aee557776694cde86a935 < 5cc4eea715a3fcf4e516662f736dfee63979465f | 5cc4eea715a3fcf4e516662f736dfee63979465f |
| linux | linux | >= b2383c90a9d691201b9aee557776694cde86a935 < 51c0ad3b7c5b01f9314758335a13f157b05fa56d | 51c0ad3b7c5b01f9314758335a13f157b05fa56d |
| linux | linux | >= b2383c90a9d691201b9aee557776694cde86a935 < e6b0adff99edf246ba1f8d464530a0438cb1cbda | e6b0adff99edf246ba1f8d464530a0438cb1cbda |
| linux | linux | >= b2383c90a9d691201b9aee557776694cde86a935 < a45ba33d398a821147d7e5f16ead7eb125e331e2 | a45ba33d398a821147d7e5f16ead7eb125e331e2 |
| linux | linux | >= b2383c90a9d691201b9aee557776694cde86a935 < 5d2b286eb034af114f67d9967fc3fbc1829bb712 | 5d2b286eb034af114f67d9967fc3fbc1829bb712 |
| linux | linux | >= b2383c90a9d691201b9aee557776694cde86a935 < 1f5661388f43df3ac106ce93e67d8d22b16a78ff | 1f5661388f43df3ac106ce93e67d8d22b16a78ff |
| linux | linux | >= b2383c90a9d691201b9aee557776694cde86a935 < cf138759a7e92c75cfc1b7ba705e4108fe330edf | cf138759a7e92c75cfc1b7ba705e4108fe330edf |
| linux | linux | >= b2383c90a9d691201b9aee557776694cde86a935 < 85db68fc901da52314ded80aace99f8b684c7815 | 85db68fc901da52314ded80aace99f8b684c7815 |
| linux | linux | >= b2383c90a9d691201b9aee557776694cde86a935 < 357057ee55d3c99a5de5abe8150f7bca04f8e53b | 357057ee55d3c99a5de5abe8150f7bca04f8e53b |
| linux | linux_kernel | >= 0 < 5.10.178-1 | 5.10.178-1 |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 4.10 < 4.14.303 | 4.14.303 |
| linux | linux_kernel | >= 4.15 < 4.19.270 | 4.19.270 |
| linux | linux_kernel | >= 4.2 < 4.9.337 | 4.9.337 |
| linux | linux_kernel | >= 4.20 < 5.4.229 | 5.4.229 |
| linux | linux_kernel | >= 5.11 < 5.15.86 | 5.15.86 |
| linux | linux_kernel | >= 5.16 < 6.0.16 | 6.0.16 |
| linux | linux_kernel | >= 5.5 < 5.10.163 | 5.10.163 |
| linux | linux_kernel | >= 6.1 < 6.1.2 | 6.1.2 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: staging: vme_user: Fix possible UAF in tsi148_dma_list_add
vendor_redhat·2025-09-18·CVSS 7.8
CVE-2022-50384 [HIGH] kernel: staging: vme_user: Fix possible UAF in tsi148_dma_list_add
kernel: staging: vme_user: Fix possible UAF in tsi148_dma_list_add
In the Linux kernel, the following vulnerability has been resolved:
staging: vme_user: Fix possible UAF in tsi148_dma_list_add
Smatch report warning as follows:
drivers/staging/vme_user/vme_tsi148.c:1757 tsi148_dma_list_add() warn:
'&entry->list' not removed from list
In tsi148_dma_list_add(), the error path "goto err_dma" will not
remove entry->list from list->entries, but entry will be freed,
then list traversal may cause UAF.
Fix by removeing it from list->entries before free().
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affect
Debian
CVE-2022-50384: linux - In the Linux kernel, the following vulnerability has been resolved: staging: vm...
vendor_debian·2022·CVSS 7.8
CVE-2022-50384 [HIGH] CVE-2022-50384: linux - In the Linux kernel, the following vulnerability has been resolved: staging: vm...
In the Linux kernel, the following vulnerability has been resolved: staging: vme_user: Fix possible UAF in tsi148_dma_list_add Smatch report warning as follows: drivers/staging/vme_user/vme_tsi148.c:1757 tsi148_dma_list_add() warn: '&entry->list' not removed from list In tsi148_dma_list_add(), the error path "goto err_dma" will not remove entry->list from list->entries, but entry will be freed, then list traversal may cause UAF. Fix by removeing it from list->entries before free().
Scope: local
bookworm: resolved (fixed in 6.1.4-1)
bullseye: resolved (fixed in 5.10.178-1)
forky: resolved (fixed in 6.1.4-1)
sid: resolved (fixed in 6.1.4-1)
trixie: resolved (fixed in 6.1.4-1)
OSV
CVE-2022-50384: In the Linux kernel, the following vulnerability has been resolved: staging: vme_user: Fix possible UAF in tsi148_dma_list_add Smatch report warning a
osv·2025-09-18·CVSS 7.8
CVE-2022-50384 [HIGH] CVE-2022-50384: In the Linux kernel, the following vulnerability has been resolved: staging: vme_user: Fix possible UAF in tsi148_dma_list_add Smatch report warning a
In the Linux kernel, the following vulnerability has been resolved: staging: vme_user: Fix possible UAF in tsi148_dma_list_add Smatch report warning as follows: drivers/staging/vme_user/vme_tsi148.c:1757 tsi148_dma_list_add() warn: '&entry->list' not removed from list In tsi148_dma_list_add(), the error path "goto err_dma" will not remove entry->list from list->entries, but entry will be freed, then list traversal may cause UAF. Fix by removeing it from list->entries before free().
GHSA
GHSA-8j88-p9vm-9wrx: In the Linux kernel, the following vulnerability has been resolved:
staging: vme_user: Fix possible UAF in tsi148_dma_list_add
Smatch report warning
ghsa_unreviewed·2025-09-18
CVE-2022-50384 [HIGH] CWE-416 GHSA-8j88-p9vm-9wrx: In the Linux kernel, the following vulnerability has been resolved:
staging: vme_user: Fix possible UAF in tsi148_dma_list_add
Smatch report warning
In the Linux kernel, the following vulnerability has been resolved:
staging: vme_user: Fix possible UAF in tsi148_dma_list_add
Smatch report warning as follows:
drivers/staging/vme_user/vme_tsi148.c:1757 tsi148_dma_list_add() warn:
'&entry->list' not removed from list
In tsi148_dma_list_add(), the error path "goto err_dma" will not
remove entry->list from list->entries, but entry will be freed,
then list traversal may cause UAF.
Fix by removeing it from list->entries before free().
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/1f5661388f43df3ac106ce93e67d8d22b16a78ffhttps://git.kernel.org/stable/c/357057ee55d3c99a5de5abe8150f7bca04f8e53bhttps://git.kernel.org/stable/c/51c0ad3b7c5b01f9314758335a13f157b05fa56dhttps://git.kernel.org/stable/c/5cc4eea715a3fcf4e516662f736dfee63979465fhttps://git.kernel.org/stable/c/5d2b286eb034af114f67d9967fc3fbc1829bb712https://git.kernel.org/stable/c/85db68fc901da52314ded80aace99f8b684c7815https://git.kernel.org/stable/c/a45ba33d398a821147d7e5f16ead7eb125e331e2https://git.kernel.org/stable/c/cf138759a7e92c75cfc1b7ba705e4108fe330edfhttps://git.kernel.org/stable/c/e6b0adff99edf246ba1f8d464530a0438cb1cbda
2025-09-18
Published