cbcvebase.
CVE-2022-50411
published 2025-09-18

CVE-2022-50411: In the Linux kernel, the following vulnerability has been resolved: ACPICA: Fix error code path in acpi_ds_call_control_method() A use-after-free in…

PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.15%
4.9th percentile
In the Linux kernel, the following vulnerability has been resolved: ACPICA: Fix error code path in acpi_ds_call_control_method() A use-after-free in acpi_ps_parse_aml() after a failing invocaion of acpi_ds_call_control_method() is reported by KASAN [1] and code inspection reveals that next_walk_state pushed to the thread by acpi_ds_create_walk_state() is freed on errors, but it is not popped from the thread beforehand. Thus acpi_ds_get_current_walk_state() called by acpi_ps_parse_aml() subsequently returns it as the new walk state which is incorrect. To address this, make acpi_ds_call_control_method() call acpi_ds_pop_walk_state() to pop next_walk_state from the thread before returning an error.

Affected

23 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.4-1 (bookworm)linux 6.1.4-1 (bookworm)
linuxlinux
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 38e251d356a01b61a86cb35213cafd7e8fe7090c38e251d356a01b61a86cb35213cafd7e8fe7090c
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < f520d181477ec29a496c0b3bbfbdb7e2606c2713f520d181477ec29a496c0b3bbfbdb7e2606c2713
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 2deb42c4f9776e59bee247c14af9c5e8c05ca9a62deb42c4f9776e59bee247c14af9c5e8c05ca9a6
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 9ef353c92f9d04c88de3af1a46859c1fb76db0f89ef353c92f9d04c88de3af1a46859c1fb76db0f8
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < b0b83d3f3ffa96e8395c56b83d6197e184902a34b0b83d3f3ffa96e8395c56b83d6197e184902a34
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 5777432ebaaf797e24f059979b42df31399671635777432ebaaf797e24f059979b42df3139967163
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 0462fec709d51762ba486245bc344f44cc6cfa970462fec709d51762ba486245bc344f44cc6cfa97
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 799881db3e03b5e98fe6a900d9d7de8c7d61e7ee799881db3e03b5e98fe6a900d9d7de8c7d61e7ee
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 404ec60438add1afadaffaed34bb5fe4ddcadd40404ec60438add1afadaffaed34bb5fe4ddcadd40
linuxlinux_kernel< 4.9.3374.9.337
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 4.10 < 4.14.3034.14.303
linuxlinux_kernel>= 4.15 < 4.19.2704.19.270
linuxlinux_kernel>= 4.20 < 5.4.2295.4.229
linuxlinux_kernel>= 5.11 < 5.15.865.15.86
linuxlinux_kernel>= 5.16 < 6.0.166.0.16
linuxlinux_kernel>= 5.5 < 5.10.1635.10.163
linuxlinux_kernel>= 6.1 < 6.1.26.1.2

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.