CVE-2022-50217

MEDIUM

Linux Kernel 5.16-5.18.18 5.19.0-5.19.2 - Use-After-Free in FUSE Release

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: fuse: write inode in fuse_release() A race between write(2) and close(2) allows pages to be dirtied after fuse_flush -> write_inode_now(). If these pages are not flushed from fuse_release(), then there might not be a writable open file later. So any remaining dirty pages must be written back before the file is released. This is a partial revert of the blamed commit.

Scores

CVSS v3 5.5
EPSS 0.0019
EPSS Percentile 8.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

Status published
Products (11)
linux/Kernel 5.16.0 - 5.18.18linux
linux/Kernel 5.19.0 - 5.19.2linux
Linux/Linux < 5.16
Linux/Linux 36ea23374d1f7b6a9d96a2b61d38830fdf23e45d - 035ff33cf4db101250fb980a3941bf078f37a544
Linux/Linux 36ea23374d1f7b6a9d96a2b61d38830fdf23e45d - 4bd9d5d20f344d015422969302d12653c903c271
Linux/Linux 36ea23374d1f7b6a9d96a2b61d38830fdf23e45d - 5ccb0420b7c9334ab8122037847101931b899301
Linux/Linux 5.16
Linux/Linux 5.18.18 - 5.18.*
Linux/Linux 5.19.2 - 5.19.*
Linux/Linux 6.0
... and 1 more
Published Jun 18, 2025
Tracked Since Feb 18, 2026