---
id: CVE-2022-50034
title: "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: cdns3 fix use-after-free at workaround 2\n\nBUG: KFENCE: use-after-free read in __list_del_entry_valid+0x10/0xac\n\ncdns3_wa2_remove_old_request()\n{\n\t...\n\tkfree(priv_r…"
summary: "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: cdns3 fix use-after-free at workaround 2\n\nBUG: KFENCE: use-after-free read in __list_del_entry_valid+0x10/0xac\n\ncdns3_wa2_remove_old_request()\n{\n\t...\n\tkfree(priv_r…"
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-416
vendor: linux
product: linux_kernel
affected:
  - 'linux_kernel >= 5.3, < 5.4.211'
  - 'linux_kernel >= 5.5, < 5.10.138'
  - 'linux_kernel >= 5.11, < 5.15.63'
  - 'linux_kernel >= 5.16, < 5.19.4'
patched:
  - linux_kernel 5.19.4
published: '2025-06-18'
updated: '2026-08-15'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2022-50034'
references:
  - url: 'https://git.kernel.org/stable/c/6d7ac60098b206d0472475b666cb09d556bec03d'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/6fd50446e7c9a98b4bcf96815f5c9602a16ea472'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/7d602f30149a117eea260208b1661bc404c21dfd'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/c3c1dbad3a2db32ecf371c97f2058491b8ba0f9a'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/e65d9b7147d7be3504893ca7dfb85286bda83d40'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
epss: 0.00193
epssPercentile: 0.07949
ingestedAt: '2026-08-15T13:26:45.069Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

usb: cdns3 fix use-after-free at workaround 2

BUG: KFENCE: use-after-free read in __list_del_entry_valid+0x10/0xac

cdns3_wa2_remove_old_request()
{
	...
	kfree(priv_req->request.buf);
	cdns3_gadget_ep_free_request(&priv_ep->endpoint, &priv_req->request);
	list_del_init(&priv_req->list);
	^^^ use after free
	...
}

cdns3_gadget_ep_free_request() free the space pointed by priv_req,
but priv_req is used in the following list_del_init().

This patch move list_del_init() before cdns3_gadget_ep_free_request().

## Affected

- `linux_kernel >= 5.3, < 5.4.211`
- `linux_kernel >= 5.5, < 5.10.138`
- `linux_kernel >= 5.11, < 5.15.63`
- `linux_kernel >= 5.16, < 5.19.4`

## Remediation

Upgrade past the affected range:

- `linux_kernel 5.19.4`
