Junglewise Threat Intelligence

CVE-2022-50785: Linux kernel FSI OCC use-after-free in device management

CVE-2022-50785 · Severity: high · CVSS 7.8 · Published 2025-12-30

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The FSI (FSP Service Interface) OCC (On-Chip Controller) driver in the Linux kernel contains a use-after-free vulnerability in device lifecycle management. An attacker with local access could exploit this by keeping file descriptors open while the device is being removed, potentially leading to memory corruption, denial of service, or arbitrary code execution with kernel privileges.

Technical details

The vulnerability is a use-after-free in the FSI OCC driver (drivers/fsi/fsi-occ.c) that occurs when a device is freed while file descriptors remain open. The root cause involves insufficient reference counting and synchronization: the occ_open() function did not increment the device reference count, allowing the device to be freed in occ_remove() even with active file descriptors. Additionally, the occ_submit() function accessed a buffer without checking if it had been freed. The fix applies get_device/put_device for proper reference counting in open/close, adds mutex protection around buffer deallocation in occ_remove(), and adds a null-check before buffer access in occ_submit(). The vulnerability affects the Linux kernel across multiple versions and requires local system access to trigger.

Affected products

  • Linux Linux kernel multiple versions; patched in commit d3e1e24604031b0d83b6c2d38f54eeea265cfcc0

Timeline

  • 2022-05-13: disclosed: Upstream fix authored by Eddie James
  • 2022-10-21: patched: Patch included in stable kernels via Sasha Levin
  • 2025-12-30: other: Advisory published

References

Related threats