cbcvebase.
CVE-2022-50462
published 2025-10-01

CVE-2022-50462: In the Linux kernel, the following vulnerability has been resolved: MIPS: vpe-mt: fix possible memory leak while module exiting Afer commit 1fa5ae857bb1…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.15%
4.6th percentile
In the Linux kernel, the following vulnerability has been resolved: MIPS: vpe-mt: fix possible memory leak while module exiting Afer commit 1fa5ae857bb1 ("driver core: get rid of struct device's bus_id string array"), the name of device is allocated dynamically, it need be freed when module exiting, call put_device() to give up reference, so that it can be freed in kobject_cleanup() when the refcount hit to 0. The vpe_device is static, so remove kfree() from vpe_device_release().

Affected

23 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.4-1 (bookworm)linux 6.1.4-1 (bookworm)
linuxlinux
linuxlinux>= 1fa5ae857bb14f6046205171d98506d8112dd74e < 170e9913c2ed5cfc37c0adf0fdbd368d2d8d8168170e9913c2ed5cfc37c0adf0fdbd368d2d8d8168
linuxlinux>= 1fa5ae857bb14f6046205171d98506d8112dd74e < 9d180e0bb21c57bd6cca2adeb672d3b522e910b59d180e0bb21c57bd6cca2adeb672d3b522e910b5
linuxlinux>= 1fa5ae857bb14f6046205171d98506d8112dd74e < 851ae5640875f06494e40002cd503b11a634c6fb851ae5640875f06494e40002cd503b11a634c6fb
linuxlinux>= 1fa5ae857bb14f6046205171d98506d8112dd74e < b3325a443525e3b89151879b834519b21c5e3011b3325a443525e3b89151879b834519b21c5e3011
linuxlinux>= 1fa5ae857bb14f6046205171d98506d8112dd74e < 48d42f4464d713fbdd79f334fdcd6e5be534cc6748d42f4464d713fbdd79f334fdcd6e5be534cc67
linuxlinux>= 1fa5ae857bb14f6046205171d98506d8112dd74e < e820a8192ff68570100347855b567512aec43819e820a8192ff68570100347855b567512aec43819
linuxlinux>= 1fa5ae857bb14f6046205171d98506d8112dd74e < b191dde84e40624d5577f64db0ec922c5c0ec57cb191dde84e40624d5577f64db0ec922c5c0ec57c
linuxlinux>= 1fa5ae857bb14f6046205171d98506d8112dd74e < ab3d47c1fd0202821abd473ca87580faafd47847ab3d47c1fd0202821abd473ca87580faafd47847
linuxlinux>= 1fa5ae857bb14f6046205171d98506d8112dd74e < 5822e8cc84ee37338ab0bdc3124f6eec04dc232d5822e8cc84ee37338ab0bdc3124f6eec04dc232d
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 2.6.30 < 4.9.3374.9.337
linuxlinux_kernel>= 4.10 < 4.14.3034.14.303
linuxlinux_kernel>= 4.15 < 4.19.2704.19.270
linuxlinux_kernel>= 4.20 < 5.4.2295.4.229
linuxlinux_kernel>= 5.11 < 5.15.865.15.86
linuxlinux_kernel>= 5.16 < 6.0.166.0.16
linuxlinux_kernel>= 5.5 < 5.10.1635.10.163
linuxlinux_kernel>= 6.1 < 6.1.26.1.2

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.