Use After Free Vulnerability in Linux Kernel dma-buf/dma-resv Component
CVE-2022-49935

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
18 June 2025

What is CVE-2022-49935?

A vulnerability has been identified in the Linux Kernel's dma-buf/dma-resv component. This issue arises when a new fence is added to a dma_resv object without verifying whether it is later than the existing fences. This oversight could enable userspace to exploit the kernel, resulting in a use after free error. A minor yet defensive code change has been introduced to mitigate this risk, highlighting the importance of backporting the fix to stable kernel versions, especially for those utilizing the dma_resv object similarly.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Linux 27836b641c1bf693c96c627388497b4e0f57441b

Linux 27836b641c1bf693c96c627388497b4e0f57441b

Linux 5.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.