cbcvebase.
CVE-2022-50292
published 2025-09-15

CVE-2022-50292: In the Linux kernel, the following vulnerability has been resolved: drm/msm/dp: fix bridge lifetime Device-managed resources allocated post component bind must…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.13%
2.8th percentile
In the Linux kernel, the following vulnerability has been resolved: drm/msm/dp: fix bridge lifetime Device-managed resources allocated post component bind must be tied to the lifetime of the aggregate DRM device or they will not necessarily be released when binding of the aggregate device is deferred. This can lead resource leaks or failure to bind the aggregate device when binding is later retried and a second attempt to allocate the resources is made. For the DP bridges, previously allocated bridges will leak on probe deferral. Fix this by amending the DP parser interface and tying the lifetime of the bridge device to the DRM device rather than DP platform device. Patchwork: https://patchwork.freedesktop.org/patch/502667/

Affected

9 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.0.7-1 (bookworm)linux 6.0.7-1 (bookworm)
linuxlinux
linuxlinux>= c3bf8e21b38a89418f2e22173b229aaad2306815 < 7eda6977e8058dd45607a5bbc6517a0f42ccd6c97eda6977e8058dd45607a5bbc6517a0f42ccd6c9
linuxlinux>= c3bf8e21b38a89418f2e22173b229aaad2306815 < 16194958f888d63839042d1190f7001e5ddec47b16194958f888d63839042d1190f7001e5ddec47b
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.0.7-16.0.7-1
linuxlinux_kernel>= 0 < 6.0.7-16.0.7-1
linuxlinux_kernel>= 0 < 6.0.7-16.0.7-1
linuxlinux_kernel>= 5.19 < 6.0.76.0.7

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.