usb: f_fs: Fix use-after-free for epfile
Published Jul 16, 2024
7.8
HIGHCVSS 3.1
EPSS 0.27%
Description
Consider a case where ffs_func_eps_disable is called from ffs_func_disable as part of composition switch and at the same time ffs_epfile_release get called from userspace. ffs_epfile_release will free up the read buffer and call ffs_data_closed which in turn destroys ffs->epfiles and mark it as NULL. While this was happening the driver has already initialized the local epfile in ffs_func_eps_disable which is now freed and waiting to acquire the spinlock. Once spinlock is acquired the driver proceeds with the stale value of epfile and tries to free the already freed read buffer causing use-after-free.
Following is the illustration of the race:
CPU1 CPU2
ffs_func_eps_disable epfiles (local copy) ffs_epfile_release ffs_data_closed if (last file closed) ffs_data_reset ffs_data_clear ffs_epfiles_destroy spin_lock dereference epfiles
Fix this races by taking epfiles local copy & assigning it under spinlock and if epfiles(local) is null then update it in ffs->epfiles then finally destroy it. Extending the scope further from the race, protecting the ep related structures, and concurrent accesses.
Affected products
-
- Version 4.8.10StatusaffectedConstraints<4.9
- Version
-
- Version StatusaffectedConstraints-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 4.9StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<4.9
- Version 4.14.267StatusunaffectedConstraints<=4.14.*
- Version 4.19.230StatusunaffectedConstraints<=4.19.*
- Version 5.10.101StatusunaffectedConstraints<=5.10.*
- Version 5.15.24StatusunaffectedConstraints<=5.15.*
- Version 5.16.10StatusunaffectedConstraints<=5.16.*
- Version 5.17StatusunaffectedConstraints<=*
- Version 5.4.180StatusunaffectedConstraints<=5.4.*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| ||||||||||||||||||||||||||||||
| Linux | Linux | unaffected |
| ||||||||||||||||||||||||||||||
| Linux | Linux | affected |
|
- ≥ 4.9 · < 4.14.267
- ≥ 4.15 · < 4.19.230
- ≥ 4.20 · < 5.4.180
- ≥ 5.5 · < 5.10.101
- ≥ 5.11 · < 5.15.24
- ≥ 5.16 · < 5.16.10
No data.
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
1 other source (Red Hat) ▾
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Sep 10, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2024–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (5 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 0.27% (0.00275) | 18.06th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.27% (0.00272) | 18.77th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.03% (0.00029) | 5.21th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.04% (0.00042) | 5.07th | v3 (v2023.03.01) |
| Jul 17, 2024 | 0.04% (0.00044) | 10.62th | v3 (v2023.03.01) |
References (12)
- https://access.redhat.com/security/cve/CVE-2022-48822 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2298161 Issue Tracking
- https://git.kernel.org/stable/c/0042178a69eb77a979e36a50dcce9794a3140ef8 Patch
- https://git.kernel.org/stable/c/32048f4be071f9a6966744243f1786f45bb22dc2 Patch
- https://git.kernel.org/stable/c/3e078b18753669615301d946297bafd69294ad2c Patch
- https://git.kernel.org/stable/c/72a8aee863af099d4434314c4536d6c9a61dcf3c Patch
- https://git.kernel.org/stable/c/c9fc422c9a43e3d58d246334a71f3390401781dc Patch
- https://git.kernel.org/stable/c/cfe5f6fd335d882bcc829a1c8a7d462a455c626e Patch
- https://git.kernel.org/stable/c/ebe2b1add1055b903e2acd86b290a85297edc0b3 Patch
- https://lore.kernel.org/linux-cve-announce/2024071650-CVE-2022-48822-48d1@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2022-48822
- https://www.cve.org/CVERecord?id=CVE-2022-48822
Change history (0)
No recorded changes yet.