PT-2025-25961 · Linux+4 · Linux Kernel+4

Published

2022-08-16

·

Updated

2025-07-15

·

CVE-2022-50035

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.20.0
Description A use-after-free issue has been identified in the Linux kernel, specifically in the drm/amdgpu component. This issue arises when amdgpu cs vm handling returns a non-zero value, causing the bo list mutex to be unlocked twice, resulting in a use-after-free problem. The issue is associated with the amdgpu cs ioctl function and can lead to a warning and potential system instability.
Recommendations For Linux kernel versions prior to 5.20.0, update to a newer version that includes the fix for the use-after-free issue on the amdgpu bo list mutex. As a temporary workaround, consider disabling the amdgpu cs vm handling function until a patch is available. Restrict access to the drm/amdgpu component to minimize the risk of exploitation. Avoid using the amdgpu cs ioctl function in sensitive operations until the issue is resolved.

Exploit

Fix

Buffer Overflow

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-04880
CESA-2023_2951
CVE-2022-50035
RHSA-2023:2458
RHSA-2023:2951
RHSA-2023_2458
RHSA-2023_2951
SUSE-SU-2025:02264-1
SUSE-SU-2025:02321-1
SUSE-SU-2025:2264-1
SUSE-SU-2025_02264-1

Affected Products

Astra Linux
Centos
Linux Kernel
Red Hat
Suse