drivers/video/fbdev/smscufx.c in the Linux kernel through 5.19.12 has a race condition and resultant use-after-free if a physically proximate attacker removes a USB device while calling open(), aka a race condition between ufxopsopen and ufxusbdisconnect.
[
{
"id": "CVE-2022-41849-8fe0b1a8",
"signature_version": "v1",
"digest": {
"function_hash": "205909523177592569613412458671004216236",
"length": 340.0
},
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@5610bcfe8693c02e2e4c8b31427f1bdbdecc839c",
"signature_type": "Function",
"target": {
"file": "drivers/video/fbdev/smscufx.c",
"function": "ufx_usb_disconnect"
}
},
{
"id": "CVE-2022-41849-e6dc3d41",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"177317986844080172460262387811667946161",
"311246331596194292562217426212667202624",
"281487104347792681598110767770856022709",
"124422754777126715584602200533122281484",
"251385027144983806713487528049749513705",
"179141780648007536727880229537180283907",
"317575162930417798625278304042102035735",
"45411140908808993951287259247477276132",
"269510233884431001392676664424404198290",
"87733423428924913227911233914352816531",
"314065151005966069606749637880587989965",
"103994959191070430733998145891422798431",
"40085230402438650370474371214530264135",
"67512918084673841298048101166125409977",
"29105287778815931506356227114306598899",
"166350475415288130479479557066864572233",
"23000422241869459352903655074670443535"
]
},
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@5610bcfe8693c02e2e4c8b31427f1bdbdecc839c",
"signature_type": "Line",
"target": {
"file": "drivers/video/fbdev/smscufx.c"
}
},
{
"id": "CVE-2022-41849-fbc70d7c",
"signature_version": "v1",
"digest": {
"function_hash": "297067271843130096655990766421897431662",
"length": 601.0
},
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@5610bcfe8693c02e2e4c8b31427f1bdbdecc839c",
"signature_type": "Function",
"target": {
"file": "drivers/video/fbdev/smscufx.c",
"function": "ufx_ops_open"
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-41849.json"