CVE-2022-50767 — Linux vulnerability
7 documents6 sources
Severity
—N/A
No vectorEPSS
0.0%
top 89.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 24
Description
In the Linux kernel, the following vulnerability has been resolved:
fbdev: smscufx: Fix several use-after-free bugs
Several types of UAFs can occur when physically removing a USB device.
Adds ufx_ops_destroy() function to .fb_destroy of fb_ops, and
in this function, there is kref_put() that finally calls ufx_free().
This fix prevents multiple UAFs.
Affected Packages4 packages
▶CVEListV5linux/linux3c8a63e22a0802fd56380f6ab305b419f18eb6f5 — 6f2075ea883e5d7730d0c9ebb1bb8e7a1a7e953f+8
🔴Vulnerability Details
3GHSA▶
GHSA-gvc9-3fj4-7qr5: In the Linux kernel, the following vulnerability has been resolved:
fbdev: smscufx: Fix several use-after-free bugs
Several types of UAFs can occur↗2025-12-24
OSV▶
CVE-2022-50767: In the Linux kernel, the following vulnerability has been resolved: fbdev: smscufx: Fix several use-after-free bugs Several types of UAFs can occur wh↗2025-12-24