PT-2025-8360 · Linux+4 · Linux Kernel+4

Jean-Philippe Brucker

·

Published

2022-05-06

·

Updated

2025-09-29

·

CVE-2022-49426

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A use-after-free issue in the Linux kernel has been identified, specifically in the io/mm/arm-smmu-v3-sva component. The problem arises from calling arm64 mm context put() without holding a reference to the mm, which can lead to the mm being freed prematurely. To address this, mmgrab() and mmdrop() are used to ensure the mm is only freed after the ASID has been unpinned.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Double Free

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
BDU:2025-04342
CESA-2022_7683
CVE-2022-49426
RHSA-2022:7683
RHSA-2022:8267
RHSA-2022_7683
RHSA-2022_8267
SUSE-SU-2025:1027-1
SUSE-SU-2025:1176-1
SUSE-SU-2025:1183-1
SUSE-SU-2025:1241-1
SUSE-SU-2025_1027-1
SUSE-SU-2025_1241-1

Affected Products

Astra Linux
Centos
Linux Kernel
Red Hat
Suse