Use-After-Free Vulnerability in Linux Kernel's SCSI Subsystem
CVE-2022-50422

7.8HIGH

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
1 October 2025

What is CVE-2022-50422?

A use-after-free vulnerability exists in the SCSI Linux kernel module due to improper timer handling in the smp_execute_task_sg() function. When a task execution fails, improper cancellation of a timer leads to potential access of deallocated memory. The flaw occurs in a multi-threaded context where one thread may free memory while another is still using it, creating a critical risk for system stability and security. The issue has been addressed by implementing a synchronized deletion of the timer to ensure that the timer's handler execution is complete before the memory is deallocated.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Linux 2908d778ab3e244900c310974e1fc1c69066e450 < 117331a2a5227fb4369c2a1f321d3e3e2e2ef8fe

Linux 2908d778ab3e244900c310974e1fc1c69066e450

Linux 2908d778ab3e244900c310974e1fc1c69066e450

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.