CVE-2022-49954: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: Input: iforce - wake up after clearing IFORCE_XMIT_RUNNING flag syzbot is reporting hung task at __input_unregister_device() [1], for iforce_close() waiting at wait_event_interruptible() with dev->mutex held is blocking input_disconnect_device() from __input_unregister_device(). It seems that the cause is simply that commit c2b27ef672992a20 ("Input: iforce - wait for command completion when closing the device") forgot to call wake_up() after clear_bit(). Fix this problem by introducing a helper that calls clear_bit() followed by wake_up_all().

Affected products

  • Linux Linux Kernel: from 2.6.34, before 5.4.213 (fixed in 5.4.213); from 5.5, before 5.10.142 (fixed in 5.10.142); from 5.11, before 5.15.66 (fixed in 5.15.66); from 5.16, before 5.19.8 (fixed in 5.19.8); version 2.6.33 only; version 6.0 only

Published 2025-06-18. Last modified 2026-06-17.