PT-2025-37607 · Linux+1 · Linux Kernel+1

Published

2022-12-05

·

Updated

2025-09-20

·

CVE-2022-50305

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel contains a flaw within the ASoC sof es8336 driver. The sof es8336 remove() function calls cancel delayed work(), which does not guarantee completion of the associated work function before the driver's remove function finishes. This can lead to a use-after-free condition if the callback function continues to execute after the driver has been removed. The issue is addressed by using cancel delayed work sync(), which ensures the work is cancelled and cannot be rescheduled.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Race Condition

Weakness Enumeration

Related Identifiers

BDU:2026-02048
CVE-2022-50305

Affected Products

Linux Kernel
Sof Es8336