CVE-2022-41849

CVSS v3.1 4.2 (Medium)
42% Progress
EPSS 0.06 % (28th)
0.06% Progress
Affected Products 2
Advisories 36

drivers/video/fbdev/smscufx.c in the Linux kernel through 5.19.12 has a race condition and resultant use-after-free if a physically proximate attacker removes a USB device while calling open(), aka a race condition between ufx_ops_open and ufx_usb_disconnect.

Weaknesses
CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CWE-416
Use After Free
CVE Status
PUBLISHED
CNA
MITRE
Published Date
2022-09-30 06:15:12
(23 months ago)
Updated Date
2024-03-25 01:15:52
(5 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Linux Kernel 5.19.12 and prior versions cpe:2.3:o:linux:linux_kernel <= 5.19.12

Configuration #2

    CPE23 From Up To
  Debian Linux 10.0 cpe:2.3:o:debian:debian_linux:10.0
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...