PT-2025-38428 · Linux+2 · Linux Kernel+2
Published
2022-11-08
·
Updated
2025-10-23
·
CVE-2022-50411
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A use-after-free issue exists in
acpi ps parse aml() following a failing invocation of acpi ds call control method(). The issue occurs because a walk state pushed to the thread is freed on errors but not popped from the thread beforehand, leading acpi ds get current walk state() to return an incorrect walk state.Recommendations
Call
acpi ds pop walk state() within acpi ds call control method() before returning an error.Exploit
Fix
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Linux Kernel
Suse