CVE-2022-50492Use After Free in Linux

CWE-416Use After Free5 documents5 sources
Severity
7.8HIGHNVD
EPSS
0.0%
top 95.25%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 4

Description

In the Linux kernel, the following vulnerability has been resolved: drm/msm: fix use-after-free on probe deferral The bridge counter was never reset when tearing down the DRM device so that stale pointers to deallocated structures would be accessed on the next tear down (e.g. after a second late bind deferral). Given enough bridges and a few probe deferrals this could currently also lead to data beyond the bridge array being corrupted. Patchwork: https://patchwork.freedesktop.org/patch/50266

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages4 packages

NVDlinux/linux_kernel3.126.0.7+1
Debianlinux/linux_kernel< 6.0.7-1+2
CVEListV5linux/linuxa3376e3ec81c5dd0622cbc187db76d2824d31c1c0a30a47741b6df1f9555a0fac6aebb7e8c363bad+2
debiandebian/linux< linux 6.0.7-1 (bookworm)

Patches

🔴Vulnerability Details

2
OSV
CVE-2022-50492: In the Linux kernel, the following vulnerability has been resolved: drm/msm: fix use-after-free on probe deferral The bridge counter was never reset w2025-10-04
GHSA
GHSA-j42x-ghgc-wq35: In the Linux kernel, the following vulnerability has been resolved: drm/msm: fix use-after-free on probe deferral The bridge counter was never reset2025-10-04

📋Vendor Advisories

2
Red Hat
kernel: drm/msm: fix use-after-free on probe deferral2025-10-04
Debian
CVE-2022-50492: linux - In the Linux kernel, the following vulnerability has been resolved: drm/msm: fi...2022