cbcvebase.
CVE-2022-50039
published 2025-06-18

CVE-2022-50039: In the Linux kernel, the following vulnerability has been resolved: stmmac: intel: Add a missing clk_disable_unprepare() call in intel_eth_pci_remove() Commit…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.20%
10.3th percentile
In the Linux kernel, the following vulnerability has been resolved: stmmac: intel: Add a missing clk_disable_unprepare() call in intel_eth_pci_remove() Commit 09f012e64e4b ("stmmac: intel: Fix clock handling on error and remove paths") removed this clk_disable_unprepare() This was partly revert by commit ac322f86b56c ("net: stmmac: Fix clock handling on remove path") which removed this clk_disable_unprepare() because: " While unloading the dwmac-intel driver, clk_disable_unprepare() is being called twice in stmmac_dvr_remove() and intel_eth_pci_remove(). This causes kernel panic on the second call. " However later on, commit 5ec55823438e8 ("net: stmmac: add clocks management for gmac driver") has updated stmmac_dvr_remove() which do not call clk_disable_unprepare() anymore. So this call should now be called from intel_eth_pci_remove().

Affected

15 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.0.2-1 (bookworm)linux 6.0.2-1 (bookworm)
linuxlinux
linuxlinux>= 3afe11be6435e126f1507ddf1a9d0e5a0d90b336 < 02f3642d8e657c05f382729c165bed46745dc18c02f3642d8e657c05f382729c165bed46745dc18c
linuxlinux>= 5.10.81 < 5.10.1385.10.138
linuxlinux>= 5ec55823438e850c91c6b92aec93fb04ebde29e2 < 47129531196054b374017555165b47a43cdb6f4147129531196054b374017555165b47a43cdb6f41
linuxlinux>= 5ec55823438e850c91c6b92aec93fb04ebde29e2 < 9400aeb419d35e718e90aa14a97c11229d0a40bc9400aeb419d35e718e90aa14a97c11229d0a40bc
linuxlinux>= 5ec55823438e850c91c6b92aec93fb04ebde29e2 < 5c23d6b717e4e956376f3852b90f58e262946b505c23d6b717e4e956376f3852b90f58e262946b50
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.140-15.10.140-1
linuxlinux_kernel>= 0 < 6.0.2-16.0.2-1
linuxlinux_kernel>= 0 < 6.0.2-16.0.2-1
linuxlinux_kernel>= 0 < 6.0.2-16.0.2-1
linuxlinux_kernel>= 5.10.81 < 5.10.1385.10.138
linuxlinux_kernel>= 5.13 < 5.15.635.15.63
linuxlinux_kernel>= 5.16 < 5.19.45.19.4

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.