{"id":"DEBIAN-CVE-2022-49686","details":"In the Linux kernel, the following vulnerability has been resolved:  usb: gadget: uvc: fix list double add in uvcg_video_pump  A panic can occur if the endpoint becomes disabled and the uvcg_video_pump adds the request back to the req_free list after it has already been queued to the endpoint. The endpoint complete will add the request back to the req_free list. Invalidate the local request handle once it's been queued.  \u003c6\u003e[  246.796704][T13726] configfs-gadget gadget: uvc: uvc_function_set_alt(1, 0) \u003c3\u003e[  246.797078][   T26] list_add double add: new=ffffff878bee5c40, prev=ffffff878bee5c40, next=ffffff878b0f0a90. \u003c6\u003e[  246.797213][   T26] ------------[ cut here ]------------ \u003c2\u003e[  246.797224][   T26] kernel BUG at lib/list_debug.c:31! \u003c6\u003e[  246.807073][   T26] Call trace: \u003c6\u003e[  246.807180][   T26]  uvcg_video_pump+0x364/0x38c \u003c6\u003e[  246.807366][   T26]  process_one_work+0x2a4/0x544 \u003c6\u003e[  246.807394][   T26]  worker_thread+0x350/0x784 \u003c6\u003e[  246.807442][   T26]  kthread+0x2ac/0x320","modified":"2026-08-27T23:04:30.341303153Z","published":"2025-02-26T07:01:43.437Z","upstream":["CVE-2022-49686"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2022-49686"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.18.14-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-49686.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.18.14-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-49686.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.18.14-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-49686.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}