PT-2025-43070 · Linux+1 · Linux Kernel+1

Published

2022-09-23

·

Updated

2025-12-04

·

CVE-2022-50560

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.19-rc6-lrmbkasan+
Description The Linux kernel has a flaw within the drm/meson subsystem. Specifically, the failure to call component master del when unloading the meson drm module causes the aggregate device to remain indefinitely in the global aggregate devices list. This issue occurs when unloading and reloading the meson dw hdmi module, leading to a use-after-free condition when component add calls try to bring up aggregate device and encounters the unbound meson drm aggregate device. This dereferencing of freed memory results in a kernel crash. The crash report indicates a read of size 8 at an invalid memory address.
Recommendations Update to a newer version of the Linux kernel that addresses this issue.

Exploit

Fix

Use After Free

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-04859
CVE-2022-50560
SUSE-SU-2025:4111-1
SUSE-SU-2025:4139-1
SUSE-SU-2025:4149-1
SUSE-SU-2025:4320-1

Affected Products

Linux Kernel
Suse