cbcvebase.
CVE-2022-50276
published 2025-09-15

CVE-2022-50276: In the Linux kernel, the following vulnerability has been resolved: power: supply: fix null pointer dereferencing in power_supply_get_battery_info when…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.15%
4.4th percentile
In the Linux kernel, the following vulnerability has been resolved: power: supply: fix null pointer dereferencing in power_supply_get_battery_info when kmalloc() fail to allocate memory in kasprintf(), propname will be NULL, strcmp() called by of_get_property() will cause null pointer dereference. So return ENOMEM if kasprintf() return NULL pointer.

Affected

17 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.4-1 (bookworm)linux 6.1.4-1 (bookworm)
linuxlinux
linuxlinux>= 3afb50d7125bcdbf71df843134e96ceffc78c8b8 < 8ea68b4e3fa9392ef9dae303abc8735a033c280f8ea68b4e3fa9392ef9dae303abc8735a033c280f
linuxlinux>= 3afb50d7125bcdbf71df843134e96ceffc78c8b8 < 5beadb55f4e36fafe5d6df5dcd5f85d803f3f1345beadb55f4e36fafe5d6df5dcd5f85d803f3f134
linuxlinux>= 3afb50d7125bcdbf71df843134e96ceffc78c8b8 < d21534ab4fd7883e1c8037a76671d4e8b6ea14cbd21534ab4fd7883e1c8037a76671d4e8b6ea14cb
linuxlinux>= 3afb50d7125bcdbf71df843134e96ceffc78c8b8 < 279af90e65cbdb3e5c4519b0043324d7876bc5ec279af90e65cbdb3e5c4519b0043324d7876bc5ec
linuxlinux>= 3afb50d7125bcdbf71df843134e96ceffc78c8b8 < b8131efb89d9f837c9244f900f0fc2699fd1181db8131efb89d9f837c9244f900f0fc2699fd1181d
linuxlinux>= 3afb50d7125bcdbf71df843134e96ceffc78c8b8 < 104bb8a663451404a26331263ce5b96c34504049104bb8a663451404a26331263ce5b96c34504049
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 5.0 < 5.4.2295.4.229
linuxlinux_kernel>= 5.11 < 5.15.865.15.86
linuxlinux_kernel>= 5.16 < 6.0.166.0.16
linuxlinux_kernel>= 5.5 < 5.10.1635.10.163
linuxlinux_kernel>= 6.1 < 6.1.26.1.2

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.