Skip to content

kernel CVE-2022-41849

Moderate
rpkelly published GHSA-jqg8-2w9w-f292 Jan 27, 2023

Package

kernel-5.10 (bottlerocket)

Affected versions

< 1.12.0

Patched versions

1.12.0

Description

drivers/video/fbdev/smscufx.c in the Linux kernel through 5.19.12 has a race condition and resultant use-after-free if a physically proximate attacker removes a USB device while calling open(), aka a race condition between ufx_ops_open and ufx_usb_disconnect.

Severity

Moderate

CVE ID

CVE-2022-41849

Weaknesses

No CWEs