cbcvebase.
CVE-2022-50454
published 2025-10-01

CVE-2022-50454: In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: fix a use-after-free in nouveau_gem_prime_import_sg_table() nouveau_bo_init()…

PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.15%
4.8th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: fix a use-after-free in nouveau_gem_prime_import_sg_table() nouveau_bo_init() is backed by ttm_bo_init() and ferries its return code back to the caller. On failures, ttm will call nouveau_bo_del_ttm() and free the memory.Thus, when nouveau_bo_init() returns an error, the gem object has already been released. Then the call to nouveau_bo_ref() will use the freed "nvbo->bo" and lead to a use-after-free bug. We should delete the call to nouveau_bo_ref() to avoid the use-after-free.

Affected

17 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.0.3-1 (bookworm)linux 6.0.3-1 (bookworm)
linuxlinux
linuxlinux>= 019cbd4a4feb3aa3a917d78e7110e3011bbff6d5 < 56ee9577915dc06f55309901012a9ef68dbdb5a856ee9577915dc06f55309901012a9ef68dbdb5a8
linuxlinux>= 019cbd4a4feb3aa3a917d78e7110e3011bbff6d5 < 5d6093c49c098d86c7b136aba9922df44aeb69445d6093c49c098d86c7b136aba9922df44aeb6944
linuxlinux>= 019cbd4a4feb3aa3a917d78e7110e3011bbff6d5 < 861f085f81fd569b02cc2c11165a9e6cca144424861f085f81fd569b02cc2c11165a9e6cca144424
linuxlinux>= 019cbd4a4feb3aa3a917d78e7110e3011bbff6d5 < 3aeda2fe6517cc52663d4ce3588dd43f0d4124a73aeda2fe6517cc52663d4ce3588dd43f0d4124a7
linuxlinux>= 019cbd4a4feb3aa3a917d78e7110e3011bbff6d5 < 7d80473e9f12548ac05b36af4fb9ce80f2f735097d80473e9f12548ac05b36af4fb9ce80f2f73509
linuxlinux>= 019cbd4a4feb3aa3a917d78e7110e3011bbff6d5 < 540dfd188ea2940582841c1c220bd035a7db0e51540dfd188ea2940582841c1c220bd035a7db0e51
linuxlinux_kernel>= 0 < 5.10.158-15.10.158-1
linuxlinux_kernel>= 0 < 6.0.3-16.0.3-1
linuxlinux_kernel>= 0 < 6.0.3-16.0.3-1
linuxlinux_kernel>= 0 < 6.0.3-16.0.3-1
linuxlinux_kernel>= 5.11 < 5.15.755.15.75
linuxlinux_kernel>= 5.16 < 5.19.175.19.17
linuxlinux_kernel>= 5.4 < 5.4.2205.4.220
linuxlinux_kernel>= 5.5 < 5.10.1505.10.150
linuxlinux_kernel>= 6.0 < 6.0.36.0.3

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.