cbcvebase.
CVE-2022-50278
published 2025-09-15

CVE-2022-50278: In the Linux kernel, the following vulnerability has been resolved: PNP: fix name memory leak in pnp_alloc_dev() After commit 1fa5ae857bb1 ("driver core: get…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.15%
4.6th percentile
In the Linux kernel, the following vulnerability has been resolved: PNP: fix name memory leak in pnp_alloc_dev() After commit 1fa5ae857bb1 ("driver core: get rid of struct device's bus_id string array"), the name of device is allocated dynamically, move dev_set_name() after pnp_add_id() to avoid memory leak.

Affected

23 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.4-1 (bookworm)linux 6.1.4-1 (bookworm)
linuxlinux
linuxlinux>= 1fa5ae857bb14f6046205171d98506d8112dd74e < ea77b4b761cd75e5456f677311babfa0418f289aea77b4b761cd75e5456f677311babfa0418f289a
linuxlinux>= 1fa5ae857bb14f6046205171d98506d8112dd74e < 693a0c13c1f0c0fcaa1e38cb806cc0789bd415aa693a0c13c1f0c0fcaa1e38cb806cc0789bd415aa
linuxlinux>= 1fa5ae857bb14f6046205171d98506d8112dd74e < bbcf772216aa237036cc3ae3158288d0a95aaf4dbbcf772216aa237036cc3ae3158288d0a95aaf4d
linuxlinux>= 1fa5ae857bb14f6046205171d98506d8112dd74e < 81b024df4755e6bb6993b786584eca6eabbb979181b024df4755e6bb6993b786584eca6eabbb9791
linuxlinux>= 1fa5ae857bb14f6046205171d98506d8112dd74e < dac87e295cddc8ab316cff14ab2071b5221d84fadac87e295cddc8ab316cff14ab2071b5221d84fa
linuxlinux>= 1fa5ae857bb14f6046205171d98506d8112dd74e < c12b314bb23dc0c83e03402cc84574700947e3b2c12b314bb23dc0c83e03402cc84574700947e3b2
linuxlinux>= 1fa5ae857bb14f6046205171d98506d8112dd74e < 1f50c7497a5f89de0c31f2edf086af41ff8343201f50c7497a5f89de0c31f2edf086af41ff834320
linuxlinux>= 1fa5ae857bb14f6046205171d98506d8112dd74e < 290dd73b943c95c006df973257076ff163adf4d0290dd73b943c95c006df973257076ff163adf4d0
linuxlinux>= 1fa5ae857bb14f6046205171d98506d8112dd74e < 110d7b0325c55ff3620073ba4201845f59e22ebf110d7b0325c55ff3620073ba4201845f59e22ebf
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 2.6.30 < 4.9.3374.9.337
linuxlinux_kernel>= 4.10 < 4.14.3034.14.303
linuxlinux_kernel>= 4.15 < 4.19.2704.19.270
linuxlinux_kernel>= 4.20 < 5.4.2295.4.229
linuxlinux_kernel>= 5.11 < 5.15.865.15.86
linuxlinux_kernel>= 5.16 < 6.0.166.0.16
linuxlinux_kernel>= 5.5 < 5.10.1635.10.163
linuxlinux_kernel>= 6.1 < 6.1.26.1.2

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.