CVE-2022-50411
HIGHLinux Kernel < 4.9.337 - Use After Free
Title source: ruleDescription
In the Linux kernel, the following vulnerability has been resolved: ACPICA: Fix error code path in acpi_ds_call_control_method() A use-after-free in acpi_ps_parse_aml() after a failing invocaion of acpi_ds_call_control_method() is reported by KASAN [1] and code inspection reveals that next_walk_state pushed to the thread by acpi_ds_create_walk_state() is freed on errors, but it is not popped from the thread beforehand. Thus acpi_ds_get_current_walk_state() called by acpi_ps_parse_aml() subsequently returns it as the new walk state which is incorrect. To address this, make acpi_ds_call_control_method() call acpi_ds_pop_walk_state() to pop next_walk_state from the thread before returning an error.
References (9)
Scores
CVSS v3
7.8
EPSS
0.0001
EPSS Percentile
2.2%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-416
Status
published
Affected Products (9)
linux/linux_kernel
< 4.9.337
linux/Kernel
< 4.9.337linux
linux/Kernel
< 4.14.303linux
linux/Kernel
< 4.19.270linux
linux/Kernel
< 5.4.229linux
linux/Kernel
< 5.10.163linux
linux/Kernel
< 5.15.86linux
linux/Kernel
< 6.0.16linux
linux/Kernel
< 6.1.2linux
Timeline
Published
Sep 18, 2025
Tracked Since
Feb 18, 2026