Junglewise Threat Intelligence

CVE-2022-50630: Linux kernel hugetlb use-after-free in hugetlb_handle_userfault

CVE-2022-50630 · Severity: high · CVSS 7.8 · Published 2025-12-08

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's hugetlb memory subsystem contains a use-after-free vulnerability in the hugetlb_handle_userfault function that manages large page allocations. A race condition can occur when locks are reacquired after handling user faults, allowing a virtual memory area to be freed while still being accessed. This could enable a local attacker to crash the system or potentially execute arbitrary code with kernel privileges.

Technical details

The vulnerability is a use-after-free (UAF) in the hugetlb_handle_userfault() function in mm/hugetlb.c. The root cause is a race condition where vma_lock and hugetlb_fault_mutex are unlocked before calling handle_userfault() to allow the mmap_lock to be dropped during userfault handling. After handle_userfault() returns, the code attempted to reacquire these locks, but in the interim, concurrent code could perform munmap operations that free the vma structure, causing a UAF when the lock is reacquired. The attack requires local access and the ability to trigger userfaultfd operations on hugetlb mappings. The fix eliminates the unnecessary reacquisition of locks after handle_userfault() returns, since the locks are dropped immediately afterward anyway. This vulnerability affects Linux kernel versions 4.14 and later.

Affected products

  • Linux Linux kernel 4.14 and later

Timeline

  • 2022-09-23: disclosed
  • 2022-10-26: patched

References

Related threats