CVE-2022-50220: usbnet: Fix linkwatch use-after-free on disconnect

Published Jun 18, 2025
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

usbnet: Fix linkwatch use-after-free on disconnect

usbnet uses the work usbnetdeferredkevent() to perform tasks which may sleep. On disconnect, completion of the work was originally awaited in ->ndostop(). But in 2003, that was moved to ->disconnect() by historic commit "[PATCH] USB: usbnet, prevent exotic rtnl deadlock":

https://git.kernel.org/tglx/history/c/0f138bbfd83c

The change was made because back then, the kernel's workqueue implementation did not allow waiting for a single work. One had to wait for completion of all work by calling flushscheduledwork(), and that could deadlock when waiting for usbnetdeferredkevent() with rtnlmutex held in ->ndostop().

The commit solved one problem but created another: It causes a use-after-free in USB Ethernet drivers aqc111.c, asixdevices.c, ax88179178a.c, ch9200.c and smsc75xx.c:

If the drivers receive a link change interrupt immediately before disconnect, they raise EVENTLINKRESET in their (non-sleepable) ->status() callback and schedule usbnetdeferredkevent(). usbnetdeferredkevent() invokes the driver's ->linkreset() callback, which calls netifcarrier{on,off}(). That in turn schedules the work linkwatchevent().

Because usbnetdeferredkevent() is awaited after unregisternetdev(), netifcarrier{on,off}() may operate on an unregistered netdev and linkwatchevent() may run after freenetdev(), causing a use-after-free.

In 2010, usbnet was changed to only wait for a single instance of usbnetdeferredkevent() instead of all work by commit 23f333a2bfaf ("drivers/net: don't use flushscheduledwork()").

Unfortunately the commit neglected to move the wait back to ->ndostop(). Rectify that omission at long last.

Affected Software

9 affected components
Linux Linux kernel
Linux Linux kernel>=2.6.38<4.9.326
Linux Linux kernel>=4.10<4.14.291
Linux Linux kernel>=4.15<4.19.256
Linux Linux kernel>=4.20<5.4.211
Linux Linux kernel>=5.5<5.10.137
Linux Linux kernel>=5.11<5.15.61
Linux Linux kernel>=5.16<5.18.18
Linux Linux kernel>=5.19<5.19.2

Event History

Jun 18, 2025
CVE Published
via MITRE·11:03 AM
Data Sourced
via MITRE·11:03 AM
Description
Data Sourced
via NVD·11:15 AM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2022-50220?

CVE-2022-50220 is classified as a medium severity vulnerability affecting the Linux kernel.

2

How do I fix CVE-2022-50220?

To fix CVE-2022-50220, update the Linux kernel to the latest version where the vulnerability has been patched.

3

What type of vulnerability is CVE-2022-50220?

CVE-2022-50220 is a use-after-free vulnerability related to the usbnet driver in the Linux kernel.

4

Which software is affected by CVE-2022-50220?

CVE-2022-50220 affects the Linux kernel across various distributions that include the impacted usbnet driver.

5

How does CVE-2022-50220 impact system security?

CVE-2022-50220 could allow an attacker to execute arbitrary code or disrupt system operations when the vulnerable component is exploited.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203