cbcvebase.
CVE-2022-50250
published 2025-09-15

CVE-2022-50250: In the Linux kernel, the following vulnerability has been resolved: regulator: core: fix use_count leakage when handling boot-on I found a use_count leakage…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.15%
4.4th percentile
In the Linux kernel, the following vulnerability has been resolved: regulator: core: fix use_count leakage when handling boot-on I found a use_count leakage towards supply regulator of rdev with boot-on option. ┌───────────────────┐ ┌───────────────────┐ │ regulator_dev A │ │ regulator_dev B │ │ (boot-on) │ │ (boot-on) │ │ use_count=0 │◀──supply──│ use_count=1 │ │ │ │ │ └───────────────────┘ └───────────────────┘ In case of rdev(A) configured with `regulator-boot-on', the use_count of supplying regulator(B) will increment inside regulator_enable(rdev->supply). Thus, B will acts like always-on, and further balanced regulator_enable/disable cannot actually disable it anymore. However, B was also configured with `regulator-boot-on', we wish it could be disabled afterwards.

Affected

21 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.4-1 (bookworm)linux 6.1.4-1 (bookworm)
linuxlinux
linuxlinux>= 089b3f61ecfc43ca4ea26d595e1d31ead6de3f7b < 4b737246ff50f810d6ab4be13c1388a07f0c14b14b737246ff50f810d6ab4be13c1388a07f0c14b1
linuxlinux>= 089b3f61ecfc43ca4ea26d595e1d31ead6de3f7b < feb847e6591e8c7a09cc39721cc9ca74fd9a5d80feb847e6591e8c7a09cc39721cc9ca74fd9a5d80
linuxlinux>= 089b3f61ecfc43ca4ea26d595e1d31ead6de3f7b < 4dd6e1cc9c7403f1ee1b7eee85bc31b797ae83474dd6e1cc9c7403f1ee1b7eee85bc31b797ae8347
linuxlinux>= 089b3f61ecfc43ca4ea26d595e1d31ead6de3f7b < bc6c381df5793ebcf32db88a3e65acf7870379fcbc6c381df5793ebcf32db88a3e65acf7870379fc
linuxlinux>= 089b3f61ecfc43ca4ea26d595e1d31ead6de3f7b < 0591b14ce0398125439c759f889647369aa616a00591b14ce0398125439c759f889647369aa616a0
linuxlinux>= 4.19.226 < 4.19.2704.19.270
linuxlinux>= 5.4.7 < 5.4.2295.4.229
linuxlinux>= dc1b1d7faf616ed663d0bba9be5abb4d1ed35d01 < dc3391d49479bc2bf8a2b88dbf86fdd800882feedc3391d49479bc2bf8a2b88dbf86fdd800882fee
linuxlinux>= f44b07472f29ae313ce875dc7b9c75b100c608b8 < 5bfc53df288e8ea54ca6866fb92034214940183f5bfc53df288e8ea54ca6866fb92034214940183f
linuxlinux_kernel< 4.19.2704.19.270
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 4.20 < 5.4.2295.4.229
linuxlinux_kernel>= 5.11 < 5.15.865.15.86
linuxlinux_kernel>= 5.16 < 6.0.166.0.16
linuxlinux_kernel>= 5.5 < 5.10.1635.10.163
linuxlinux_kernel>= 6.1 < 6.1.26.1.2

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.