{"id":"CVE-2022-50034","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: cdns3 fix use-after-free at workaround 2\n\nBUG: KFENCE: use-after-free read in __list_del_entry_valid+0x10/0xac\n\ncdns3_wa2_remove_old_request()\n{\n\t...\n\tkfree(priv_r…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: cdns3 fix use-after-free at workaround 2\n\nBUG: KFENCE: use-after-free read in __list_del_entry_valid+0x10/0xac\n\ncdns3_wa2_remove_old_request()\n{\n\t...\n\tkfree(priv_r…","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-416"],"vendor":"linux","product":"linux_kernel","affected":["linux_kernel >= 5.3, < 5.4.211","linux_kernel >= 5.5, < 5.10.138","linux_kernel >= 5.11, < 5.15.63","linux_kernel >= 5.16, < 5.19.4"],"patched":["linux_kernel 5.19.4"],"published":"2025-06-18","updated":"2026-08-15","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2022-50034","references":[{"url":"https://git.kernel.org/stable/c/6d7ac60098b206d0472475b666cb09d556bec03d","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6fd50446e7c9a98b4bcf96815f5c9602a16ea472","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7d602f30149a117eea260208b1661bc404c21dfd","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c3c1dbad3a2db32ecf371c97f2058491b8ba0f9a","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e65d9b7147d7be3504893ca7dfb85286bda83d40","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd"],"epss":0.00193,"epssPercentile":0.0929,"ingestedAt":"2026-08-15T13:26:45.069Z","slug":"CVE-2022-50034","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nusb: cdns3 fix use-after-free at workaround 2\n\nBUG: KFENCE: use-after-free read in __list_del_entry_valid+0x10/0xac\n\ncdns3_wa2_remove_old_request()\n{\n\t...\n\tkfree(priv_req->request.buf);\n\tcdns3_gadget_ep_free_request(&priv_ep->endpoint, &priv_req->request);\n\tlist_del_init(&priv_req->list);\n\t^^^ use after free\n\t...\n}\n\ncdns3_gadget_ep_free_request() free the space pointed by priv_req,\nbut priv_req is used in the following list_del_init().\n\nThis patch move list_del_init() before cdns3_gadget_ep_free_request().\n\n## Affected\n\n- `linux_kernel >= 5.3, < 5.4.211`\n- `linux_kernel >= 5.5, < 5.10.138`\n- `linux_kernel >= 5.11, < 5.15.63`\n- `linux_kernel >= 5.16, < 5.19.4`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `linux_kernel 5.19.4`","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}