CVE-2022-41849: Debian Linux
Medium severity, CVSS 4.2. EPSS: 0.3% chance of exploitation in the next 30 days.
drivers/video/fbdev/smscufx.c in the Linux kernel through 5.19.12 has a race condition and resultant use-after-free if a physically proximate attacker removes a USB device while calling open(), aka a race condition between ufx_ops_open and ufx_usb_disconnect.
Affected products
Published 2022-09-30. Last modified 2026-06-17.