cbcvebase.
CVE-2022-50389
published 2025-09-18

CVE-2022-50389: In the Linux kernel, the following vulnerability has been resolved: tpm: tpm_crb: Add the missed acpi_put_table() to fix memory leak In crb_acpi_add(), we get…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.15%
4.3th percentile
In the Linux kernel, the following vulnerability has been resolved: tpm: tpm_crb: Add the missed acpi_put_table() to fix memory leak In crb_acpi_add(), we get the TPM2 table to retrieve information like start method, and then assign them to the priv data, so the TPM2 table is not used after the init, should be freed, call acpi_put_table() to fix the memory leak.

Affected

21 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.4-1 (bookworm)linux 6.1.4-1 (bookworm)
linuxlinux
linuxlinux>= 30fc8d138e9123f374a3c3867e7c7c5cd4004941 < 08fd965521d0e172d540cf945517810895fcb19908fd965521d0e172d540cf945517810895fcb199
linuxlinux>= 30fc8d138e9123f374a3c3867e7c7c5cd4004941 < 1af2232b13837ce0f3a082b9f43735b09aafc3671af2232b13837ce0f3a082b9f43735b09aafc367
linuxlinux>= 30fc8d138e9123f374a3c3867e7c7c5cd4004941 < 927860dfa161ae8392a264197257dbdc52b26b0f927860dfa161ae8392a264197257dbdc52b26b0f
linuxlinux>= 30fc8d138e9123f374a3c3867e7c7c5cd4004941 < 0bd9b4be721c776f77adcaf34105dfca3007ddb90bd9b4be721c776f77adcaf34105dfca3007ddb9
linuxlinux>= 30fc8d138e9123f374a3c3867e7c7c5cd4004941 < 986cd9a9b95423e35a2cbb8e9105aec0e0d7f337986cd9a9b95423e35a2cbb8e9105aec0e0d7f337
linuxlinux>= 30fc8d138e9123f374a3c3867e7c7c5cd4004941 < 2fcd3dc8b97a14f1672729c86b7041a1a89b052a2fcd3dc8b97a14f1672729c86b7041a1a89b052a
linuxlinux>= 30fc8d138e9123f374a3c3867e7c7c5cd4004941 < b0785edaf649e5f04dc7f75533e810f4c00e4106b0785edaf649e5f04dc7f75533e810f4c00e4106
linuxlinux>= 30fc8d138e9123f374a3c3867e7c7c5cd4004941 < 37e90c374dd11cf4919c51e847c6d6ced0abc55537e90c374dd11cf4919c51e847c6d6ced0abc555
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 4.0 < 4.14.3034.14.303
linuxlinux_kernel>= 4.15 < 4.19.2704.19.270
linuxlinux_kernel>= 4.20 < 5.4.2295.4.229
linuxlinux_kernel>= 5.11 < 5.15.875.15.87
linuxlinux_kernel>= 5.16 < 6.0.176.0.17
linuxlinux_kernel>= 5.5 < 5.10.1635.10.163
linuxlinux_kernel>= 6.1 < 6.1.36.1.3

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.