CVE-2022-50389Missing Release of Memory after Effective Lifetime in Linux

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 95.77%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 18

Description

In the Linux kernel, the following vulnerability has been resolved: tpm: tpm_crb: Add the missed acpi_put_table() to fix memory leak In crb_acpi_add(), we get the TPM2 table to retrieve information like start method, and then assign them to the priv data, so the TPM2 table is not used after the init, should be freed, call acpi_put_table() to fix the memory leak.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages4 packages

NVDlinux/linux_kernel4.04.14.303+6
Debianlinux/linux_kernel< 5.10.178-1+3
CVEListV5linux/linux30fc8d138e9123f374a3c3867e7c7c5cd400494108fd965521d0e172d540cf945517810895fcb199+8
debiandebian/linux< linux 6.1.4-1 (bookworm)

Patches

🔴Vulnerability Details

2
OSV
CVE-2022-50389: In the Linux kernel, the following vulnerability has been resolved: tpm: tpm_crb: Add the missed acpi_put_table() to fix memory leak In crb_acpi_add()2025-09-18
GHSA
GHSA-gmpx-hjjv-xj6f: In the Linux kernel, the following vulnerability has been resolved: tpm: tpm_crb: Add the missed acpi_put_table() to fix memory leak In crb_acpi_add2025-09-18

📋Vendor Advisories

2
Red Hat
kernel: tpm: tpm_crb: Add the missed acpi_put_table() to fix memory leak2025-09-18
Debian
CVE-2022-50389: linux - In the Linux kernel, the following vulnerability has been resolved: tpm: tpm_cr...2022
CVE-2022-50389 — Linux vulnerability | cvebase