Use-After-Free Vulnerability in Linux Kernel ACPICA Component
CVE-2022-50411
What is CVE-2022-50411?
A use-after-free vulnerability exists in the Linux kernel's ACPICA component, specifically in the function acpi_ps_parse_aml(). The issue arises after a failed invocation of acpi_ds_call_control_method(), where a state variable is improperly handled. When an error occurs, the variable next_walk_state is freed but not properly removed from the thread context, leading to incorrect state retrieval during subsequent function calls. This vulnerability could potentially allow for unauthorized access or manipulation of kernel memory, thus necessitating timely security measures and patches to mitigate risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 38e251d356a01b61a86cb35213cafd7e8fe7090c
Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 2deb42c4f9776e59bee247c14af9c5e8c05ca9a6
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved