CVE-2022-49685

Source
https://nvd.nist.gov/vuln/detail/CVE-2022-49685
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-49685.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2022-49685
Downstream
Related
Published
2025-02-26T02:24:12.143Z
Modified
2025-11-28T02:33:49.429368Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
iio: trigger: sysfs: fix use-after-free on remove
Details

In the Linux kernel, the following vulnerability has been resolved:

iio: trigger: sysfs: fix use-after-free on remove

Ensure that the irq_work has completed before the trigger is freed.

================================================================== BUG: KASAN: use-after-free in irqworkrun_list Read of size 8 at addr 0000000064702248 by task python3/25

Call Trace: irqworkrunlist irqworktick updateprocesstimes tickschedhandle tickschedtimer _hrtimerrunqueues hrtimer_interrupt

Allocated by task 25: kmemcachealloctrace iiosysfstrigadd devattrstore sysfskfwrite kernfsfopwriteiter newsyncwrite vfswrite ksyswrite syswrite

Freed by task 25: kfree iiosysfstrigremove devattrstore sysfskfwrite kernfsfopwriteiter newsyncwrite vfswrite ksyswrite sys_write

==================================================================

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/49xxx/CVE-2022-49685.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
f38bc926d022ebd67baad6ac7fc22c95fbc6238c
Fixed
d6111e7bdb8ec27eb43d01c4cd4ff1620a75f7f2
Fixed
fd5d8fb298a2866c337da635c79d63c3afabcaf7
Fixed
31ff3309b47d98313c61b8301bf595820cc3cc33
Fixed
5e39397d60dacc7f5d81d442c1c958eaaaf31128
Fixed
b07a30a774b3c3e584a68dc91779c68ea2da4813
Fixed
4687c3f955240ca2a576bdc3f742d4d915b6272d
Fixed
4ef1e521be610b720daeb7cf899fedc7db0274c4
Fixed
78601726d4a59a291acc5a52da1d3a0a6831e4e8

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.7.0
Fixed
4.9.321
Type
ECOSYSTEM
Events
Introduced
4.10.0
Fixed
4.14.286
Type
ECOSYSTEM
Events
Introduced
4.15.0
Fixed
4.19.250
Type
ECOSYSTEM
Events
Introduced
4.20.0
Fixed
5.4.202
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.127
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.51
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
5.18.8