cbcvebase.
CVE-2022-50281
published 2025-09-15

CVE-2022-50281: In the Linux kernel, the following vulnerability has been resolved: MIPS: SGI-IP27: Fix platform-device leak in bridge_platform_create() In error case in…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.14%
4.2th percentile
In the Linux kernel, the following vulnerability has been resolved: MIPS: SGI-IP27: Fix platform-device leak in bridge_platform_create() In error case in bridge_platform_create after calling platform_device_add()/platform_device_add_data()/ platform_device_add_resources(), release the failed 'pdev' or it will be leak, call platform_device_put() to fix this problem. Besides, 'pdev' is divided into 'pdev_wd' and 'pdev_bd', use platform_device_unregister() to release sgi_w1 resources when xtalk-bridge registration fails.

Affected

15 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.0.3-1 (bookworm)linux 6.0.3-1 (bookworm)
linuxlinux
linuxlinux>= 5dc76a96e95ae041c1d8e52714bd77576b35919b < da2aecef866b476438d02c662507a0e4e818da9dda2aecef866b476438d02c662507a0e4e818da9d
linuxlinux>= 5dc76a96e95ae041c1d8e52714bd77576b35919b < 93296e7ab774230b7c36541dead10b6da39b650f93296e7ab774230b7c36541dead10b6da39b650f
linuxlinux>= 5dc76a96e95ae041c1d8e52714bd77576b35919b < d7ac29e60d0ff71e9e414af595b8c92800f7fa90d7ac29e60d0ff71e9e414af595b8c92800f7fa90
linuxlinux>= 5dc76a96e95ae041c1d8e52714bd77576b35919b < 48025893b3e31b917ad654d28d23fff66681cac448025893b3e31b917ad654d28d23fff66681cac4
linuxlinux>= 5dc76a96e95ae041c1d8e52714bd77576b35919b < 11bec9cba4de06b3c0e9e4041453c2caaa1cbec111bec9cba4de06b3c0e9e4041453c2caaa1cbec1
linuxlinux_kernel>= 0 < 5.10.158-15.10.158-1
linuxlinux_kernel>= 0 < 6.0.3-16.0.3-1
linuxlinux_kernel>= 0 < 6.0.3-16.0.3-1
linuxlinux_kernel>= 0 < 6.0.3-16.0.3-1
linuxlinux_kernel>= 5.11 < 5.15.755.15.75
linuxlinux_kernel>= 5.16 < 5.19.175.19.17
linuxlinux_kernel>= 5.5 < 5.10.1505.10.150
linuxlinux_kernel>= 6.0 < 6.0.36.0.3

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.