cbcvebase.
CVE-2022-50331
published 2025-09-15

CVE-2022-50331: In the Linux kernel, the following vulnerability has been resolved: wwan_hwsim: fix possible memory leak in wwan_hwsim_dev_new() Inject fault while probing…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.14%
4.1th percentile
In the Linux kernel, the following vulnerability has been resolved: wwan_hwsim: fix possible memory leak in wwan_hwsim_dev_new() Inject fault while probing module, if device_register() fails, but the refcount of kobject is not decreased to 0, the name allocated in dev_set_name() is leaked. Fix this by calling put_device(), so that name can be freed in callback function kobject_cleanup(). unreferenced object 0xffff88810152ad20 (size 8): comm "modprobe", pid 252, jiffies 4294849206 (age 22.713s) hex dump (first 8 bytes): 68 77 73 69 6d 30 00 ff hwsim0.. backtrace: [] __kmalloc_node_track_caller+0x44/0x1b0 [] kvasprintf+0xb5/0x140 [] kvasprintf_const+0x55/0x180 [] kobject_set_name_vargs+0x56/0x150 [] dev_set_name+0xab/0xe0

Affected

11 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.0.6-1 (bookworm)linux 6.0.6-1 (bookworm)
linuxlinux
linuxlinux>= f36a111a74e71edbba27d4c0cf3d7bbccc172108 < 50c31fa952309536c6e4461ff815ddccc8dff9d550c31fa952309536c6e4461ff815ddccc8dff9d5
linuxlinux>= f36a111a74e71edbba27d4c0cf3d7bbccc172108 < d87973314aba6de80a49f4271dd9be4ddc08e729d87973314aba6de80a49f4271dd9be4ddc08e729
linuxlinux>= f36a111a74e71edbba27d4c0cf3d7bbccc172108 < 258ad2fe5ede773625adfda88b173f4123e59f45258ad2fe5ede773625adfda88b173f4123e59f45
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.0.6-16.0.6-1
linuxlinux_kernel>= 0 < 6.0.6-16.0.6-1
linuxlinux_kernel>= 0 < 6.0.6-16.0.6-1
linuxlinux_kernel>= 5.14 < 5.15.765.15.76
linuxlinux_kernel>= 5.16 < 6.0.66.0.6

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.