boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2022-49968MEDIUM
Linux Linux — ieee802154/adf7242: defer destroy_workqueue call
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   H   L   N  U  N  N  H    4.7   .0022   13.1     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    58e9683d14752debc6f22daf6b23e031787df31f –  —
  Linux    4.18 –                                      4.19.258
TIMELINE
  Jun 18  Reserved by Linux
  Jun 18  Published (CNA: Linux)
  Aug 4   RESCORED — CVE-2022-49968 (Linux). CVSS 8 → 4.7 (NVD).
CWE-362, CWE-416 · CNA: Linux · CVSS v3.1 · 6 references · NVD status: Modified

Description

In the Linux kernel, the following vulnerability has been resolved: ieee802154/adf7242: defer destroy_workqueue call There is a possible race condition (use-after-free) like below (FREE) | (USE) adf7242_remove | adf7242_channel cancel_delayed_work_sync | destroy_workqueue (1) | adf7242_cmd_rx | mod_delayed_work (2) | The root cause for this race is that the upper layer (ieee802154) is unaware of this detaching event and the function adf7242_channel can be called without any checks. To fix this, we can add a flag write at the beginning of adf7242_remove and add flag check in adf7242_channel. Or we can just defer the destructive operation like other commit 3e0588c291d6 ("hamradio: defer ax25 kfree after unregister_netdev") which let the ieee802154_unregister_hw() to handle the synchronization. This patch takes the second option. runs")

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
June 18, 2025ReservedReserved by Linux
June 18, 2025PublishedPublished (CNA: Linux)
August 4, 2026RESCOREDRESCORED — CVE-2022-49968 (Linux). CVSS 8 → 4.7 (NVD).

Affected

Affected products and packages — 2 rows
VendorProduct / PackageEcosystemVersion introducedFixed
LinuxLinux58e9683d14752debc6f22daf6b23e031787df31f
LinuxLinux4.184.19.258

Weaknesses

CWE-362 · CWE-416

References (6)

Related

Authoritative record: CVE-2022-49968 at cve.org

Vendors: linux

Weaknesses: CWE-362 · CWE-416

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2022-49968 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.