CVE-2022-50283Use After Free in Linux

Severity
7.8HIGHNVD
EPSS
0.0%
top 94.20%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 15

Description

In the Linux kernel, the following vulnerability has been resolved: mtd: core: add missing of_node_get() in dynamic partitions code This fixes unbalanced of_node_put(): [ 1.078910] 6 cmdlinepart partitions found on MTD device gpmi-nand [ 1.085116] Creating 6 MTD partitions on "gpmi-nand": [ 1.090181] 0x000000000000-0x000008000000 : "nandboot" [ 1.096952] 0x000008000000-0x000009000000 : "nandfit" [ 1.103547] 0x000009000000-0x00000b000000 : "nandkernel" [ 1.110317] 0x00000b000000-0x00000c000000

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages4 packages

NVDlinux/linux_kernel6.06.0.7+1
Debianlinux/linux_kernel< 6.0.7-1+2
CVEListV5linux/linuxad9b10d1eaada169bd764abcab58f08538877e269e54ce00505d291ef88f2c05e5eef46269daf83c+2
debiandebian/linux< linux 6.0.7-1 (bookworm)

Patches

🔴Vulnerability Details

2
OSV
CVE-2022-50283: In the Linux kernel, the following vulnerability has been resolved: mtd: core: add missing of_node_get() in dynamic partitions code This fixes unbalan2025-09-15
GHSA
GHSA-cv22-jrqw-mx35: In the Linux kernel, the following vulnerability has been resolved: mtd: core: add missing of_node_get() in dynamic partitions code This fixes unbal2025-09-15

📋Vendor Advisories

2
Red Hat
kernel: mtd: core: add missing of_node_get() in dynamic partitions code2025-09-15
Debian
CVE-2022-50283: linux - In the Linux kernel, the following vulnerability has been resolved: mtd: core: ...2022
CVE-2022-50283 — Use After Free in Linux | cvebase