suse · CVE-2022-50274

Quick triage

Priority: high Published: 2025-10-05 00:53:18 UTC Updated: 2026-03-05 04:09:39 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2022-50274 severity important: SUSE including 46 source package names (bpftool-4.18.0-553.el8_10, cluster-md-kmp-default, …), 296 product×package rows across 55 product lines (SLES-LTSS-TERADATA 15 SP2, SUSE Liberty Linux 8, … (55 product lines)): Known Not Affected 276, Fixed 20.

Description:

In the Linux kernel, the following vulnerability has been resolved: media: dvbdev: adopts refcnt to avoid UAF dvb_unregister_device() is known that prone to use-after-free. That is, the cleanup from dvb_unregister_device() releases the dvb_device even if there are pointers stored in file->private_data still refer to it. This patch adds a reference counter into struct dvb_device and delays its deallocation until no pointer refers to the object.

cvelogic Threat Intelligence