{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2022-50245","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2025-09-15T13:58:00.972Z","datePublished":"2025-09-15T14:02:03.353Z","dateUpdated":"2026-05-11T19:15:34.798Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-05-11T19:15:34.798Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nrapidio: fix possible UAF when kfifo_alloc() fails\n\nIf kfifo_alloc() fails in mport_cdev_open(), goto err_fifo and just free\npriv. But priv is still in the chdev->file_list, then list traversal\nmay cause UAF. This fixes the following smatch warning:\n\ndrivers/rapidio/devices/rio_mport_cdev.c:1930 mport_cdev_open() warn: '&priv->list' not removed from list"}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/rapidio/devices/rio_mport_cdev.c"],"versions":[{"version":"e8de370188d098bb49483c287b44925957c3c9b6","lessThan":"2a6c75adf8192f07ddcdd4a1a13488c890a73919","status":"affected","versionType":"git"},{"version":"e8de370188d098bb49483c287b44925957c3c9b6","lessThan":"2dfd60724d271a6ab99f93f40f38f2ced1ddbb87","status":"affected","versionType":"git"},{"version":"e8de370188d098bb49483c287b44925957c3c9b6","lessThan":"a253dde0403a153075ffb254f6f7b2635e49e97a","status":"affected","versionType":"git"},{"version":"e8de370188d098bb49483c287b44925957c3c9b6","lessThan":"311b488405ac45af46756b1c8f1d27007b68b07e","status":"affected","versionType":"git"},{"version":"e8de370188d098bb49483c287b44925957c3c9b6","lessThan":"5ee850645e42f541ce1ea8130c2b27cc495f965c","status":"affected","versionType":"git"},{"version":"e8de370188d098bb49483c287b44925957c3c9b6","lessThan":"2f5cc7fd73fd6253cc71214f0dd499cc62feb469","status":"affected","versionType":"git"},{"version":"e8de370188d098bb49483c287b44925957c3c9b6","lessThan":"2ba06e57f933f0eac242e8b389433da1cc00d4d5","status":"affected","versionType":"git"},{"version":"e8de370188d098bb49483c287b44925957c3c9b6","lessThan":"cb87af2c19c0993f6e21f75b963a5599c5a73e76","status":"affected","versionType":"git"},{"version":"e8de370188d098bb49483c287b44925957c3c9b6","lessThan":"02d7d89f816951e0862147d751b1150d67aaebdd","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/rapidio/devices/rio_mport_cdev.c"],"versions":[{"version":"4.6","status":"affected"},{"version":"0","lessThan":"4.6","status":"unaffected","versionType":"semver"},{"version":"4.9.337","lessThanOrEqual":"4.9.*","status":"unaffected","versionType":"semver"},{"version":"4.14.303","lessThanOrEqual":"4.14.*","status":"unaffected","versionType":"semver"},{"version":"4.19.270","lessThanOrEqual":"4.19.*","status":"unaffected","versionType":"semver"},{"version":"5.4.229","lessThanOrEqual":"5.4.*","status":"unaffected","versionType":"semver"},{"version":"5.10.163","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.86","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.0.16","lessThanOrEqual":"6.0.*","status":"unaffected","versionType":"semver"},{"version":"6.1.2","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.6","versionEndExcluding":"4.9.337"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.6","versionEndExcluding":"4.14.303"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.6","versionEndExcluding":"4.19.270"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.6","versionEndExcluding":"5.4.229"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.6","versionEndExcluding":"5.10.163"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.6","versionEndExcluding":"5.15.86"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.6","versionEndExcluding":"6.0.16"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.6","versionEndExcluding":"6.1.2"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.6","versionEndExcluding":"6.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/2a6c75adf8192f07ddcdd4a1a13488c890a73919"},{"url":"https://git.kernel.org/stable/c/2dfd60724d271a6ab99f93f40f38f2ced1ddbb87"},{"url":"https://git.kernel.org/stable/c/a253dde0403a153075ffb254f6f7b2635e49e97a"},{"url":"https://git.kernel.org/stable/c/311b488405ac45af46756b1c8f1d27007b68b07e"},{"url":"https://git.kernel.org/stable/c/5ee850645e42f541ce1ea8130c2b27cc495f965c"},{"url":"https://git.kernel.org/stable/c/2f5cc7fd73fd6253cc71214f0dd499cc62feb469"},{"url":"https://git.kernel.org/stable/c/2ba06e57f933f0eac242e8b389433da1cc00d4d5"},{"url":"https://git.kernel.org/stable/c/cb87af2c19c0993f6e21f75b963a5599c5a73e76"},{"url":"https://git.kernel.org/stable/c/02d7d89f816951e0862147d751b1150d67aaebdd"}],"title":"rapidio: fix possible UAF when kfifo_alloc() fails","x_generator":{"engine":"bippy-1.2.0"}}}}