{"id":"DEBIAN-CVE-2022-49685","details":"In the Linux kernel, the following vulnerability has been resolved:  iio: trigger: sysfs: fix use-after-free on remove  Ensure that the irq_work has completed before the trigger is freed.   ==================================================================  BUG: KASAN: use-after-free in irq_work_run_list  Read of size 8 at addr 0000000064702248 by task python3/25   Call Trace:   irq_work_run_list   irq_work_tick   update_process_times   tick_sched_handle   tick_sched_timer   __hrtimer_run_queues   hrtimer_interrupt   Allocated by task 25:   kmem_cache_alloc_trace   iio_sysfs_trig_add   dev_attr_store   sysfs_kf_write   kernfs_fop_write_iter   new_sync_write   vfs_write   ksys_write   sys_write   Freed by task 25:   kfree   iio_sysfs_trig_remove   dev_attr_store   sysfs_kf_write   kernfs_fop_write_iter   new_sync_write   vfs_write   ksys_write   sys_write   ==================================================================","modified":"2026-09-01T16:05:33.038668282Z","published":"2025-02-26T07:01:43.340Z","upstream":["CVE-2022-49685"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2022-49685"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.18.14-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-49685.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.18.14-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-49685.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.18.14-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-49685.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}