PT-2022-6862 · Linux+4 · Linux Kernel+4

Hyunwoo Kim

·

Published

2022-11-25

·

Updated

2026-05-26

·

CVE-2022-45888

CVSS v3.1

6.4

Medium

VectorAV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions through 6.0.9
Description An issue was discovered in the Linux kernel, where the xillyusb.c file in the drivers/char/xillybus directory has a race condition and use-after-free during physical removal of a USB device. This issue is related to concurrent access to a shared resource with incorrect synchronization, which may allow an attacker to execute arbitrary code.
Recommendations For Linux kernel versions through 6.0.9, consider disabling the xillyusb.c driver or restricting its use until a patch is available. As a temporary workaround, avoid physically removing USB devices while the system is in use to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

DoS

Race Condition

Use After Free

Weakness Enumeration

Related Identifiers

ALT-PU-2022-3220
ALT-PU-2022-3303
ALT-PU-2022-3364
ALT-PU-2022-3371
ALT-PU-2023-1684
ALT-PU-2023-1741
ALT-PU-2023-1814
ALT-PU-2023-4894
AZL-11487
BDU:2023-05194
CVE-2022-45888
DLA-4008-1
DSA-5818-1
OPENSUSE-SU-2022_4504-1
OPENSUSE-SU-2022_4585-1
OPENSUSE-SU-2022_4617-1
OPENSUSE-SU-2024:12560-1
OPENSUSE-SU-2024:13704-1
SUSE-SU-2022:4504-1
SUSE-SU-2022:4585-1
SUSE-SU-2022:4617-1

Affected Products

Alt Linux
Astra Linux
Linux Kernel
Red Os
Suse