VDB

CVE-2022-50384

CVE-2022-50384 PUBLISHED CVSS 7.800000190734863 HIGH

In the Linux kernel, the following vulnerability has been resolved: staging: vme_user: Fix possible UAF in tsi148_dma_list_add Smatch report warning as follows: drivers/staging/vme_user/vme_tsi148.c:1757 tsi148_dma_list_add() warn: '&entry->list' not removed from list In tsi148_dma_list_add(), the error path "goto err_dma" will not remove entry->list from list->entries, but entry will be freed, then list traversal may cause UAF. Fix by removeing it from list->entries before free().

EPSS 0.02% · 5.9th percentile

Risk Scores

CVSS 3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.02%
5.9th percentile

Affected Products

VendorProductVersions
linuxlinux_kernel4.2, 4.2, 4.2
LinuxLinuxb2383c90a9d691201b9aee557776694cde86a935, b2383c90a9d691201b9aee557776694cde86a935, b2383c90a9d691201b9aee557776694cde86a935

Timeline

  • Sep 18, 2025 CVE Published
  • Sep 19, 2025 EPSS Score
  • Sep 26, 2025 EPSS Score
  • Oct 3, 2025 EPSS Score
  • Oct 10, 2025 EPSS Score
  • Oct 17, 2025 EPSS Score
  • Oct 24, 2025 EPSS Score
  • Oct 31, 2025 EPSS Score
  • Nov 7, 2025 EPSS Score
  • Nov 14, 2025 EPSS Score
  • Nov 21, 2025 EPSS Score
  • Nov 28, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›