CVE-2022-50229
Published: Jun 18, 2025
Modified: May 11, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: ALSA: bcd2000: Fix a UAF bug on the error path of probing When the driver fails in snd_card_register() at probe time, it will free the 'bcd2k->midi_out_urb' before killing it, which may cause a UAF bug. The following log can reveal it: [ 50.727020] BUG: KASAN: use-after-free in bcd2000_input_complete+0x1f1/0x2e0 [snd_bcd2000] [ 50.727623] Read of size 8 at addr ffff88810fab0e88 by task swapper/4/0 [ 50.729530] Call Trace: [ 50.732899] bcd2000_input_complete+0x1f1/0x2e0 [snd_bcd2000] Fix this by adding usb_kill_urb() before usb_free_urb().
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected b47a22290d581277be70e8a597824a4985d39e83 - < a718eba7e458e2f40531be3c6b6a0028ca7fcaceaffected b47a22290d581277be70e8a597824a4985d39e83 - < 4fc41f7ebb7efca282f1740ea934d16f33c1d109affected b47a22290d581277be70e8a597824a4985d39e83 - < 5e7338f4dd92b2f8915a82abfa1dd3ad3464bea0affected b47a22290d581277be70e8a597824a4985d39e83 - < 05e0bb8c3c4dde3e21b9c1cf9395afb04e8b24dbaffected b47a22290d581277be70e8a597824a4985d39e83 - < 348620464a5c127399ac09b266f494f393661952+4 more versions |
Linux | Linux | affected 3.16unaffected 0 - < 3.16unaffected 4.9.326 - <= 4.9.*unaffected 4.14.291 - <= 4.14.*unaffected 4.19.256 - <= 4.19.*+6 more versions |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now