CVE-2022-50420Missing Release of Memory after Effective Lifetime in Linux

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 95.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 1

Description

In the Linux kernel, the following vulnerability has been resolved: crypto: hisilicon/hpre - fix resource leak in remove process In hpre_remove(), when the disable operation of qm sriov failed, the following logic should continue to be executed to release the remaining resources that have been allocated, instead of returning directly, otherwise there will be resource leakage.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages4 packages

NVDlinux/linux_kernel5.55.15.86+2
Debianlinux/linux_kernel< 6.1.4-1+2
CVEListV5linux/linuxc8b4b477079d1995cc0a1c10d5cdfd02be938cdf2b3e3ecdb402ff1053ee25b598ff21b9ddf4384f+4
debiandebian/linux< linux 6.1.4-1 (bookworm)

Patches

🔴Vulnerability Details

2
GHSA
GHSA-26j6-p6xc-9625: In the Linux kernel, the following vulnerability has been resolved: crypto: hisilicon/hpre - fix resource leak in remove process In hpre_remove(), w2025-10-01
OSV
CVE-2022-50420: In the Linux kernel, the following vulnerability has been resolved: crypto: hisilicon/hpre - fix resource leak in remove process In hpre_remove(), whe2025-10-01

📋Vendor Advisories

2
Red Hat
kernel: crypto: hisilicon/hpre - fix resource leak in remove process2025-10-01
Debian
CVE-2022-50420: linux - In the Linux kernel, the following vulnerability has been resolved: crypto: his...2022