#VU120735 Use-after-free in Linux kernel - CVE-2022-50840
Published: December 30, 2025 / Updated: December 31, 2025
Vulnerability identifier: #VU120735
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2022-50840
CWE-ID: CWE-416
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerable software:
Linux kernel
Linux kernel
Software vendor:
Linux Foundation
Linux Foundation
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a use-after-free error within the snic_tgt_create() function in drivers/scsi/snic/snic_disc.c. A local user can escalate privileges on the system.
Remediation
Install update from vendor's repository.
External links
- https://git.kernel.org/stable/c/1895e908b3ae66a5312fd1b2cdda2da82993dca7
- https://git.kernel.org/stable/c/3007f96ca20c848d0b1b052df6d2cb5ae5586e78
- https://git.kernel.org/stable/c/3772319e40527e6a5f2ec1d729e01f271d818f5c
- https://git.kernel.org/stable/c/4141cd9e8b3379aea52a85d2c35f6eaf26d14e86
- https://git.kernel.org/stable/c/6866154c23fba40888ad6d554cccd4bf2edb755e
- https://git.kernel.org/stable/c/ad27f74e901fc48729733c88818e6b96c813057d
- https://git.kernel.org/stable/c/c7f0f8dab1ae5def57c1a8a9cafd6fabe1dc27cc
- https://git.kernel.org/stable/c/e118df492320176af94deec000ae034cc92be754
- https://git.kernel.org/stable/c/f9d8b8ba0f1a16cde0b1fc9e80466df76b6db8ff
- https://mirrors.edge.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.337