In the Linux kernel, the following vulnerability has been resolved:
staging: vmeuser: Fix possible UAF in tsi148dmalistadd
Smatch report warning as follows:
drivers/staging/vmeuser/vmetsi148.c:1757 tsi148dmalist_add() warn: '&entry->list' not removed from list
In tsi148dmalistadd(), the error path "goto errdma" will not remove entry->list from list->entries, but entry will be freed, then list traversal may cause UAF.
Fix by removeing it from list->entries before free().
{
"cna_assigner": "Linux",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/50xxx/CVE-2022-50384.json"
}