cbcvebase.
CVE-2022-50352
published 2025-09-16

CVE-2022-50352: In the Linux kernel, the following vulnerability has been resolved: net: hns: fix possible memory leak in hnae_ae_register() Inject fault while probing module…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.15%
4.4th percentile
In the Linux kernel, the following vulnerability has been resolved: net: hns: fix possible memory leak in hnae_ae_register() Inject fault while probing module, if device_register() fails, but the refcount of kobject is not decreased to 0, the name allocated in dev_set_name() is leaked. Fix this by calling put_device(), so that name can be freed in callback function kobject_cleanup(). unreferenced object 0xffff00c01aba2100 (size 128): comm "systemd-udevd", pid 1259, jiffies 4294903284 (age 294.152s) hex dump (first 32 bytes): 68 6e 61 65 30 00 00 00 18 21 ba 1a c0 00 ff ff hnae0....!...... 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ backtrace: [] slab_post_alloc_hook+0xa0/0x3e0 [] __kmem_cache_alloc_node+0x164/0x2b0 [] __kmalloc_node_track_caller+0x6c/0x390 [] kvasprintf+0x8c/0x118 [] kvasprintf_const+0x60/0xc8 [] kobject_set_name_vargs+0x3c/0xc0 [] dev_set_name+0x7c/0xa0 [] hnae_ae_register+0xcc/0x190 [hnae] [] hns_dsaf_ae_init+0x9c/0x108 [hns_dsaf] [] hns_dsaf_probe+0x548/0x748 [hns_dsaf]

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.0.6-1 (bookworm)linux 6.0.6-1 (bookworm)
linuxlinux
linuxlinux>= 6fe6611ff275522a4e4c0359e2f46cdd07780d2f < a3c148955c22fe1d94d7a2096005679c1f22eddfa3c148955c22fe1d94d7a2096005679c1f22eddf
linuxlinux>= 6fe6611ff275522a4e4c0359e2f46cdd07780d2f < 3b78453cca046d3b03853f0d077ad3ad130db8863b78453cca046d3b03853f0d077ad3ad130db886
linuxlinux>= 6fe6611ff275522a4e4c0359e2f46cdd07780d2f < 7ae1345f6ad715acbcdc9e1ac28153684fd498bb7ae1345f6ad715acbcdc9e1ac28153684fd498bb
linuxlinux>= 6fe6611ff275522a4e4c0359e2f46cdd07780d2f < dfc0337c6dceb6449403b33ecb141f4a1458a1e9dfc0337c6dceb6449403b33ecb141f4a1458a1e9
linuxlinux>= 6fe6611ff275522a4e4c0359e2f46cdd07780d2f < 2974f3b330ef25f5d34a4948d04290c2cd7802cf2974f3b330ef25f5d34a4948d04290c2cd7802cf
linuxlinux>= 6fe6611ff275522a4e4c0359e2f46cdd07780d2f < 91f8f5342bee726ed5692583d58f69e7cc9ae60e91f8f5342bee726ed5692583d58f69e7cc9ae60e
linuxlinux>= 6fe6611ff275522a4e4c0359e2f46cdd07780d2f < 02dc0db19d944b4a90941db505ecf1aaec714be402dc0db19d944b4a90941db505ecf1aaec714be4
linuxlinux>= 6fe6611ff275522a4e4c0359e2f46cdd07780d2f < ff2f5ec5d009844ec28f171123f9e58750cef4bfff2f5ec5d009844ec28f171123f9e58750cef4bf
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.158-15.10.158-1
linuxlinux_kernel>= 0 < 6.0.6-16.0.6-1
linuxlinux_kernel>= 0 < 6.0.6-16.0.6-1
linuxlinux_kernel>= 0 < 6.0.6-16.0.6-1
linuxlinux_kernel>= 4.10 < 4.14.2984.14.298
linuxlinux_kernel>= 4.15 < 4.19.2644.19.264
linuxlinux_kernel>= 4.20 < 5.4.2215.4.221
linuxlinux_kernel>= 4.4 < 4.9.3324.9.332
linuxlinux_kernel>= 5.11 < 5.15.765.15.76
linuxlinux_kernel>= 5.16 < 6.0.66.0.6
linuxlinux_kernel>= 5.5 < 5.10.1525.10.152

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.