CVE-2022-50384

Source
https://cve.org/CVERecord?id=CVE-2022-50384
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-50384.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2022-50384
Downstream
Published
2025-09-18T13:33:05.759Z
Modified
2026-05-07T04:18:46.728398Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
staging: vme_user: Fix possible UAF in tsi148_dma_list_add
Details

In the Linux kernel, the following vulnerability has been resolved:

staging: vmeuser: Fix possible UAF in tsi148dmalistadd

Smatch report warning as follows:

drivers/staging/vmeuser/vmetsi148.c:1757 tsi148dmalist_add() warn: '&entry->list' not removed from list

In tsi148dmalistadd(), the error path "goto errdma" will not remove entry->list from list->entries, but entry will be freed, then list traversal may cause UAF.

Fix by removeing it from list->entries before free().

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/50xxx/CVE-2022-50384.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
b2383c90a9d691201b9aee557776694cde86a935
Fixed
5cc4eea715a3fcf4e516662f736dfee63979465f
Fixed
51c0ad3b7c5b01f9314758335a13f157b05fa56d
Fixed
e6b0adff99edf246ba1f8d464530a0438cb1cbda
Fixed
a45ba33d398a821147d7e5f16ead7eb125e331e2
Fixed
5d2b286eb034af114f67d9967fc3fbc1829bb712
Fixed
1f5661388f43df3ac106ce93e67d8d22b16a78ff
Fixed
cf138759a7e92c75cfc1b7ba705e4108fe330edf
Fixed
85db68fc901da52314ded80aace99f8b684c7815
Fixed
357057ee55d3c99a5de5abe8150f7bca04f8e53b

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-50384.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.2.0
Fixed
4.9.337
Type
ECOSYSTEM
Events
Introduced
4.10.0
Fixed
4.14.303
Type
ECOSYSTEM
Events
Introduced
4.15.0
Fixed
4.19.270
Type
ECOSYSTEM
Events
Introduced
4.20.0
Fixed
5.4.229
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.163
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.86
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.0.16
Type
ECOSYSTEM
Events
Introduced
6.1.0
Fixed
6.1.2

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-50384.json"