PT-2025-43070 · Linux+1 · Linux Kernel+1
Published
2022-09-23
·
Updated
2025-12-04
·
CVE-2022-50560
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:S/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 5.19-rc6-lrmbkasan+
Description
The Linux kernel has a flaw within the drm/meson subsystem. Specifically, the failure to call
component master del when unloading the meson drm module causes the aggregate device to remain indefinitely in the global aggregate devices list. This issue occurs when unloading and reloading the meson dw hdmi module, leading to a use-after-free condition when component add calls try to bring up aggregate device and encounters the unbound meson drm aggregate device. This dereferencing of freed memory results in a kernel crash. The crash report indicates a read of size 8 at an invalid memory address.Recommendations
Update to a newer version of the Linux kernel that addresses this issue.
Exploit
Fix
Use After Free
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel
Suse