CVE-2022-49524 Details
Description
In the Linux kernel, the following vulnerability has been resolved: media: pci: cx23885: Fix the error handling in cx23885_initdev() When the driver fails to call the dma_set_mask(), the driver will get the following splat: [ 55.853884] BUG: KASAN: use-after-free in __process_removed_driver+0x3c/0x240 [ 55.854486] Read of size 8 at addr ffff88810de60408 by task modprobe/590 [ 55.856822] Call Trace: [ 55.860327] __process_removed_driver+0x3c/0x240 [ 55.861347] bus_for_each_dev+0x102/0x160 [ 55.861681] i2c_del_driver+0x2f/0x50 This is because the driver has initialized the i2c related resources in cx23885_dev_setup() but not released them in error handling, fix this bug by modifying the error path that jumps after failing to call the dma_set_mask().
A use-after-free vulnerability has been identified in the Linux kernel's cx23885 PCI driver. This issue arises in the error handling of the cx23885_initdev() function. When the driver fails to set the DMA mask, it inadvertently leads to a use-after-free condition. The vulnerability occurs because the driver initializes I2C-related resources in the cx23885_dev_setup() function but fails to release them during error handling. As a result, this oversight causes a read of freed memory, which can be exploited.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 27, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/453514a874c78df1e7804e6e3aaa60c8d8deb6a8 | kernel.org | Patch |
| https://git.kernel.org/stable/c/6041d1a0365baa729b6adfb6ed5386d9388018db | kernel.org | Patch |
| https://git.kernel.org/stable/c/7b9978e1c94e569d65a0e7e719abb9340f5db4a0 | kernel.org | Patch |
| https://git.kernel.org/stable/c/86bd6a579c6c60547706cabf299cd2c9feab3332 | kernel.org | Patch |
| https://git.kernel.org/stable/c/98106f100f50c487469903b9cf6d966785fc9cc3 | kernel.org | Patch |
| https://git.kernel.org/stable/c/ca17e7a532d1a55466cc007b3f4d319541a27493 | kernel.org | Patch |
| https://git.kernel.org/stable/c/e8123311cf06d7dae71e8c5fe78e0510d20cd30b | kernel.org | Patch |
| https://git.kernel.org/stable/c/fa636e9ee4442215cd9a2e079cd5a8e1fe0cb8ba | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-416 | Use After Free | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | < 4.14.283 >= 4.15, < 4.19.247 >= 4.20, < 5.4.198 >= 5.5, < 5.10.121 >= 5.11, < 5.15.46 >= 5.16, < 5.17.14 >= 5.18, < 5.18.3 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 24, 2025 | Initial Analysis | [email protected] |
| Feb 27, 2025 | CVE Modified | CISA-ADP |
| Feb 26, 2025 | New CVE Received | kernel.org |