SB20251226135 - Use-after-free in Linux kernel video fbdev driver
Published: December 26, 2025 Updated: December 31, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Use-after-free (CVE-ID: CVE-2022-50767)
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a use-after-free error within the ufx_free(), ufx_release_urb_work(), ufx_free_framebuffer_work(), ufx_ops_release(), ufx_usb_probe() and ufx_usb_disconnect() functions in drivers/video/fbdev/smscufx.c. A local user can escalate privileges on the system.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/3f40852d671072836fb7ae331a1f28a24223c4e8
- https://git.kernel.org/stable/c/5385af2f89bc352fb70753ab41b2bb036190141f
- https://git.kernel.org/stable/c/6f2075ea883e5d7730d0c9ebb1bb8e7a1a7e953f
- https://git.kernel.org/stable/c/70faf9d9b6cc74418716bbf76fe75bd2da10ad4a
- https://git.kernel.org/stable/c/8d924b262f3178a9b17c17d4306a9f426c508bd9
- https://git.kernel.org/stable/c/cc67482c9e5f2c80d62f623bcc347c29f9f648e1
- https://git.kernel.org/stable/c/cc6a7249842fceda7574ceb63275a2d5e99d2862
- https://git.kernel.org/stable/c/d9ddfeb01fb95ffbbc7031d46a5ee2a5e45cbb86
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.153