🛡️ CVE-2022-50568 — kernel

⚪ Unknown ✅ No Known Exploit NVD
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

usb: gadget: f_hid: fix f_hidg lifetime vs cdev

In the Linux kernel, the following vulnerability has been resolved:

usb: gadget: f_hid: fix f_hidg lifetime vs cdev

The embedded struct cdev does not have its lifetime correctly tied to

the enclosing struct f_hidg, so there is a use-after-free if /dev/hidgN

is held open while the gadget is deleted.

This can readily be replicated with libusbgx's example programs (for

conciseness - operating directly via configfs is equivalent):

gadget-hid

exec 3<> /dev/hidg0

gadget-vid-pid-remove

exec 3<&-

Pull the existing device up in to struct f_hidg and make use of the

cdev_device_{add,del}() helpers. This changes the lifetime of the

device object to match struct f_hidg, but note that it is still added

and deleted at the same time.

Affected software

CVE-2022-50568 is recorded against 2 packages.

  • kernel (from 6.1.0 up to 6.1.2)
  • unknown

Timeline and source

Published on 22 October 2025 and last revised on 12 August 2026. No public exploit is currently recorded for this entry. Record sourced from NVD.

References

git.kernel.org (Web)
git.kernel.org (Web)
git.kernel.org (Web)
git.kernel.org (Web)
git.kernel.org (Web)
git.kernel.org (Web)
git.kernel.org (Web)
github.com (Advisory)
nvd.nist.gov (Advisory)
git.kernel.org (Package)

CVE-2022-50568 on other distributions

Each distribution ships its own build and its own fixed version. Pick the one you run:

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source NVD
Published 2025-10-22
Updated 2026-08-20
Modified 2026-08-12
Fix URL N/A

Affected Packages

Software From version Fixed in
kernel 6.1.0 6.1.2
unknown

Similar Threats

Free Vulnerability Check

Is your site affected by CVE-2022-50568?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against CVE-2022-50568 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesCVECVE 2022