CVE-2022-49685

Source
https://cve.org/CVERecord?id=CVE-2022-49685
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-49685.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2022-49685
Downstream
Related
Published
2025-02-26T02:24:12.143Z
Modified
2026-03-12T03:25:33.515260Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
iio: trigger: sysfs: fix use-after-free on remove
Details

In the Linux kernel, the following vulnerability has been resolved:

iio: trigger: sysfs: fix use-after-free on remove

Ensure that the irq_work has completed before the trigger is freed.

================================================================== BUG: KASAN: use-after-free in irqworkrun_list Read of size 8 at addr 0000000064702248 by task python3/25

Call Trace: irqworkrunlist irqworktick updateprocesstimes tickschedhandle ticksched_timer _hrtimerrunqueues hrtimerinterrupt

Allocated by task 25: kmemcachealloctrace iiosysfstrigadd devattrstore sysfskfwrite kernfsfopwriteiter newsyncwrite vfswrite ksyswrite syswrite

Freed by task 25: kfree iiosysfstrigremove devattrstore sysfskfwrite kernfsfopwriteiter newsyncwrite vfswrite ksyswrite sys_write

==================================================================

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/49xxx/CVE-2022-49685.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
f38bc926d022ebd67baad6ac7fc22c95fbc6238c
Fixed
d6111e7bdb8ec27eb43d01c4cd4ff1620a75f7f2
Fixed
fd5d8fb298a2866c337da635c79d63c3afabcaf7
Fixed
31ff3309b47d98313c61b8301bf595820cc3cc33
Fixed
5e39397d60dacc7f5d81d442c1c958eaaaf31128
Fixed
b07a30a774b3c3e584a68dc91779c68ea2da4813
Fixed
4687c3f955240ca2a576bdc3f742d4d915b6272d
Fixed
4ef1e521be610b720daeb7cf899fedc7db0274c4
Fixed
78601726d4a59a291acc5a52da1d3a0a6831e4e8

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-49685.json"