CVE-2022-50417: Linux Kernel
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: drm/panfrost: Fix GEM handle creation ref-counting panfrost_gem_create_with_handle() previously returned a BO but with the only reference being from the handle, which user space could in theory guess and release, causing a use-after-free. Additionally if the call to panfrost_gem_mapping_get() in panfrost_ioctl_create_bo() failed then a(nother) reference on the BO was dropped. The _create_with_handle() is a problematic pattern, so ditch it and instead create the handle in panfrost_ioctl_create_bo(). If the call to panfrost_gem_mapping_get() fails then this means that user space has indeed gone behind our back and freed the handle. In which case just return an error code.
Affected products
- Linux Linux Kernel: from 5.2, before 5.10.163 (fixed in 5.10.163); from 5.11, before 5.15.87 (fixed in 5.15.87); from 5.16, before 6.0.19 (fixed in 6.0.19); from 6.1, before 6.1.5 (fixed in 6.1.5); version 6.2 only
Published 2025-09-18. Last modified 2026-06-17.