CVE-2022-50767
Estado: AplazadaSin puntuar—
In the Linux kernel, the following vulnerability has been resolved:
fbdev: smscufx: Fix several use-after-free bugs
Several types of UAFs can occur when physically removing a USB device.
Adds ufx_ops_destroy() function to .fb_destroy of fb_ops, and in this function, there is kref_put() that finally calls ufx_free().
This fix prevents multiple UAFs.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.25%
- Percentil entre todas las CVEs puntuadas: 15
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/3f40852d671072836fb7ae331a1f28a24223c4e8
- https://git.kernel.org/stable/c/5385af2f89bc352fb70753ab41b2bb036190141f
- https://git.kernel.org/stable/c/6f2075ea883e5d7730d0c9ebb1bb8e7a1a7e953f
- https://git.kernel.org/stable/c/70faf9d9b6cc74418716bbf76fe75bd2da10ad4a
- https://git.kernel.org/stable/c/8d924b262f3178a9b17c17d4306a9f426c508bd9
- https://git.kernel.org/stable/c/cc67482c9e5f2c80d62f623bcc347c29f9f648e1
- https://git.kernel.org/stable/c/cc6a7249842fceda7574ceb63275a2d5e99d2862
- https://git.kernel.org/stable/c/d9ddfeb01fb95ffbbc7031d46a5ee2a5e45cbb86
JSON original (NVD)
Mostrar
{
"id": "CVE-2022-50767",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "3c8a63e22a0802fd56380f6ab305b419f18eb6f5",
"lessThan": "6f2075ea883e5d7730d0c9ebb1bb8e7a1a7e953f",
"versionType": "git"
},
{
"status": "affected",
"version": "3c8a63e22a0802fd56380f6ab305b419f18eb6f5",
"lessThan": "3f40852d671072836fb7ae331a1f28a24223c4e8",
"versionType": "git"
},
{
"status": "affected",
"version": "3c8a63e22a0802fd56380f6ab305b419f18eb6f5",
"lessThan": "70faf9d9b6cc74418716bbf76fe75bd2da10ad4a",
"versionType": "git"
},
{
"status": "affected",
"version": "3c8a63e22a0802fd56380f6ab305b419f18eb6f5",
"lessThan": "5385af2f89bc352fb70753ab41b2bb036190141f",
"versionType": "git"
},
{
"status": "affected",
"version": "3c8a63e22a0802fd56380f6ab305b419f18eb6f5",
"lessThan": "d9ddfeb01fb95ffbbc7031d46a5ee2a5e45cbb86",
"versionType": "git"
},
{
"status": "affected",
"version": "3c8a63e22a0802fd56380f6ab305b419f18eb6f5",
"lessThan": "cc6a7249842fceda7574ceb63275a2d5e99d2862",
"versionType": "git"
},
{
"status": "affected",
"version": "3c8a63e22a0802fd56380f6ab305b419f18eb6f5",
"lessThan": "8d924b262f3178a9b17c17d4306a9f426c508bd9",
"versionType": "git"
},
{
"status": "affected",
"version": "3c8a63e22a0802fd56380f6ab305b419f18eb6f5",
"lessThan": "cc67482c9e5f2c80d62f623bcc347c29f9f648e1",
"versionType": "git"
}
],
"programFiles": [
"drivers/video/fbdev/smscufx.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "3.2"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "3.2",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "4.9.332",
"versionType": "semver",
"lessThanOrEqual": "4.9.*"
},
{
"status": "unaffected",
"version": "4.14.298",
"versionType": "semver",
"lessThanOrEqual": "4.14.*"
},
{
"status": "unaffected",
"version": "4.19.264",
"versionType": "semver",
"lessThanOrEqual": "4.19.*"
},
{
"status": "unaffected",
"version": "5.4.223",
"versionType": "semver",
"lessThanOrEqual": "5.4.*"
},
{
"status": "unaffected",
"version": "5.10.153",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.77",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.0.7",
"versionType": "semver",
"lessThanOrEqual": "6.0.*"
},
{
"status": "unaffected",
"version": "6.1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/video/fbdev/smscufx.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2025-12-24T13:16:03.503",
"references": [
{
"url": "https://git.kernel.org/stable/c/3f40852d671072836fb7ae331a1f28a24223c4e8",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/5385af2f89bc352fb70753ab41b2bb036190141f",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/6f2075ea883e5d7730d0c9ebb1bb8e7a1a7e953f",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/70faf9d9b6cc74418716bbf76fe75bd2da10ad4a",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/8d924b262f3178a9b17c17d4306a9f426c508bd9",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/cc67482c9e5f2c80d62f623bcc347c29f9f648e1",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/cc6a7249842fceda7574ceb63275a2d5e99d2862",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/d9ddfeb01fb95ffbbc7031d46a5ee2a5e45cbb86",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Deferred",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: smscufx: Fix several use-after-free bugs\n\nSeveral types of UAFs can occur when physically removing a USB device.\n\nAdds ufx_ops_destroy() function to .fb_destroy of fb_ops, and\nin this function, there is kref_put() that finally calls ufx_free().\n\nThis fix prevents multiple UAFs."
}
],
"lastModified": "2026-06-17T05:24:08.567",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}