{"id":"DEBIAN-CVE-2022-50220","details":"In the Linux kernel, the following vulnerability has been resolved:  usbnet: Fix linkwatch use-after-free on disconnect  usbnet uses the work usbnet_deferred_kevent() to perform tasks which may sleep.  On disconnect, completion of the work was originally awaited in -\u003endo_stop().  But in 2003, that was moved to -\u003edisconnect() by historic commit \"[PATCH] USB: usbnet, prevent exotic rtnl deadlock\":    https://git.kernel.org/tglx/history/c/0f138bbfd83c  The change was made because back then, the kernel's workqueue implementation did not allow waiting for a single work.  One had to wait for completion of *all* work by calling flush_scheduled_work(), and that could deadlock when waiting for usbnet_deferred_kevent() with rtnl_mutex held in -\u003endo_stop().  The commit solved one problem but created another:  It causes a use-after-free in USB Ethernet drivers aqc111.c, asix_devices.c, ax88179_178a.c, ch9200.c and smsc75xx.c:  * If the drivers receive a link change interrupt immediately before   disconnect, they raise EVENT_LINK_RESET in their (non-sleepable)   -\u003estatus() callback and schedule usbnet_deferred_kevent(). * usbnet_deferred_kevent() invokes the driver's -\u003elink_reset() callback,   which calls netif_carrier_{on,off}(). * That in turn schedules the work linkwatch_event().  Because usbnet_deferred_kevent() is awaited after unregister_netdev(), netif_carrier_{on,off}() may operate on an unregistered netdev and linkwatch_event() may run after free_netdev(), causing a use-after-free.  In 2010, usbnet was changed to only wait for a single instance of usbnet_deferred_kevent() instead of *all* work by commit 23f333a2bfaf (\"drivers/net: don't use flush_scheduled_work()\").  Unfortunately the commit neglected to move the wait back to -\u003endo_stop().  Rectify that omission at long last.","modified":"2026-09-01T20:04:57.889095982Z","published":"2025-06-18T11:15:52.973Z","upstream":["CVE-2022-50220"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2022-50220"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.0.2-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2022-50220.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.0.2-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2022-50220.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.0.2-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2022-50220.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}