PT-2025-26018 · Linux+4 · Linux Kernel+4

Published

2022-07-15

·

Updated

2025-07-28

·

CVE-2022-50092

CVSS v2.0

6.0

Medium

VectorAV:L/AC:H/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.19.0-rc6
Description A use-after-free issue has been identified in the Linux kernel, specifically in the dm sm register threshold callback function. This issue can be triggered when a metadata commit fails, causing the transaction to be aborted and the metadata space maps to be destroyed. If a DM table reload then happens for this failed thin-pool, a use-after-free will occur. The issue can be reproduced using specific commands, including echoing "offline" to /sys/block/sda/device/state, using dd to write to /dev/mapper/thin, and loading a pool using dmsetup.
Recommendations For Linux kernel versions prior to 5.19.0-rc6, consider updating to a newer version to resolve the issue. As a temporary workaround, consider disabling the dm sm register threshold callback function until a patch is available. Additionally, restrict access to the dm pool register metadata threshold function to minimize the risk of exploitation. Avoid using the dmsetup command with the load pool option until the issue is resolved.

Exploit

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-02805
CESA-2022_7683
CVE-2022-50092
RHSA-2022:7683
RHSA-2022:8267
RHSA-2022_7683
RHSA-2022_8267
SUSE-SU-2025:02264-1
SUSE-SU-2025:02308-1
SUSE-SU-2025:02320-1
SUSE-SU-2025:02321-1
SUSE-SU-2025:02322-1
SUSE-SU-2025:02334-1
SUSE-SU-2025:02537-1
SUSE-SU-2025:2264-1
SUSE-SU-2025_02264-1
SUSE-SU-2025_02308-1
SUSE-SU-2025_02334-1
SUSE-SU-2025_02537-1

Affected Products

Astra Linux
Centos
Linux Kernel
Red Hat
Suse