CVE-2022-50229 Details
Description
In the Linux kernel, the following vulnerability has been resolved: ALSA: bcd2000: Fix a UAF bug on the error path of probing When the driver fails in snd_card_register() at probe time, it will free the 'bcd2k->midi_out_urb' before killing it, which may cause a UAF bug. The following log can reveal it: [ 50.727020] BUG: KASAN: use-after-free in bcd2000_input_complete+0x1f1/0x2e0 [snd_bcd2000] [ 50.727623] Read of size 8 at addr ffff88810fab0e88 by task swapper/4/0 [ 50.729530] Call Trace: [ 50.732899] bcd2000_input_complete+0x1f1/0x2e0 [snd_bcd2000] Fix this by adding usb_kill_urb() before usb_free_urb().
A use-after-free vulnerability has been identified in the Linux kernel's ALSA bcd2000 driver. This issue arises during the probe phase when the driver fails to register a sound card. The driver incorrectly frees a USB request block (URB) for MIDI output before properly terminating it, leading to a use-after-free condition. This vulnerability can be exploited when the freed memory is accessed again, potentially causing memory corruption or arbitrary code execution.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/05e0bb8c3c4dde3e21b9c1cf9395afb04e8b24db | kernel.org | Patch |
| https://git.kernel.org/stable/c/1d6a246cf97c380f2da76591f03019dd9c9599c3 | kernel.org | Patch |
| https://git.kernel.org/stable/c/348620464a5c127399ac09b266f494f393661952 | kernel.org | Patch |
| https://git.kernel.org/stable/c/4fc41f7ebb7efca282f1740ea934d16f33c1d109 | kernel.org | Patch |
| https://git.kernel.org/stable/c/5e7338f4dd92b2f8915a82abfa1dd3ad3464bea0 | kernel.org | Patch |
| https://git.kernel.org/stable/c/64ca7f50ad96c2c65ae390b954925a36eabe04aa | kernel.org | Patch |
| https://git.kernel.org/stable/c/a718eba7e458e2f40531be3c6b6a0028ca7fcace | kernel.org | Patch |
| https://git.kernel.org/stable/c/b0d4af0a4763ddc02344789ef2a281c494bc330d | kernel.org | Patch |
| https://git.kernel.org/stable/c/ffb2759df7efbc00187bfd9d1072434a13a54139 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-416 | Use After Free | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 3.16, < 4.9.326 >= 4.10, < 4.14.291 >= 4.15, < 4.19.256 >= 4.20, < 5.4.211 >= 5.5, < 5.10.137 >= 5.11, < 5.15.61 >= 5.16, < 5.18.18 >= 5.19, < 5.19.2 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| Nov 19, 2025 | Initial Analysis | [email protected] |
| Jun 18, 2025 | New CVE Received | kernel.org |