CVE-2022-50767: Linux
EPSS: 0.3% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: fbdev: smscufx: Fix several use-after-free bugs Several types of UAFs can occur when physically removing a USB device. Adds ufx_ops_destroy() function to .fb_destroy of fb_ops, and in this function, there is kref_put() that finally calls ufx_free(). This fix prevents multiple UAFs.
Affected products
- Linux Linux: from 3.2, before 4.9.332 (fixed in 4.9.332); from 4.10, before 4.14.298 (fixed in 4.14.298); from 4.15, before 4.19.264 (fixed in 4.19.264); from 4.20, before 5.4.223 (fixed in 5.4.223); from 5.5, before 5.10.153 (fixed in 5.10.153); from 5.11, before 5.15.77 (fixed in 5.15.77); …
Published 2025-12-24. Last modified 2026-06-17.