cbcvebase.
CVE-2022-50474
published 2025-10-04

CVE-2022-50474: In the Linux kernel, the following vulnerability has been resolved: macintosh: fix possible memory leak in macio_add_one_device() Afer commit 1fa5ae857bb1…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.15%
4.9th percentile
In the Linux kernel, the following vulnerability has been resolved: macintosh: fix possible memory leak in macio_add_one_device() Afer commit 1fa5ae857bb1 ("driver core: get rid of struct device's bus_id string array"), the name of device is allocated dynamically. It needs to be freed when of_device_register() fails. Call put_device() to give up the reference that's taken in device_initialize(), so that it can be freed in kobject_cleanup() when the refcount hits 0. macio device is freed in macio_release_dev(), so the kfree() can be removed.

Affected

23 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.4-1 (bookworm)linux 6.1.4-1 (bookworm)
linuxlinux
linuxlinux>= 1fa5ae857bb14f6046205171d98506d8112dd74e < 3a866ff6fc2232c8e393cdb55ffb8ce947349e033a866ff6fc2232c8e393cdb55ffb8ce947349e03
linuxlinux>= 1fa5ae857bb14f6046205171d98506d8112dd74e < aa9054267366ff0a382d403d17728e21951ddbb9aa9054267366ff0a382d403d17728e21951ddbb9
linuxlinux>= 1fa5ae857bb14f6046205171d98506d8112dd74e < 35858b87a943917fa30172aa4bf01ce7adbcb42c35858b87a943917fa30172aa4bf01ce7adbcb42c
linuxlinux>= 1fa5ae857bb14f6046205171d98506d8112dd74e < b29a2f1dd33ae9b94821ab2f4d398b9081786748b29a2f1dd33ae9b94821ab2f4d398b9081786748
linuxlinux>= 1fa5ae857bb14f6046205171d98506d8112dd74e < 2ac0a7059b7bcbed35bfffa34a82c9a9e99638ef2ac0a7059b7bcbed35bfffa34a82c9a9e99638ef
linuxlinux>= 1fa5ae857bb14f6046205171d98506d8112dd74e < 19ded60b40e86b0903c8d5bd0161437ed5107a8b19ded60b40e86b0903c8d5bd0161437ed5107a8b
linuxlinux>= 1fa5ae857bb14f6046205171d98506d8112dd74e < ca765257feb89dacf604ced9cd233db5f865dee0ca765257feb89dacf604ced9cd233db5f865dee0
linuxlinux>= 1fa5ae857bb14f6046205171d98506d8112dd74e < 76837e7f6b30da72ad59f56291e22804a219e01576837e7f6b30da72ad59f56291e22804a219e015
linuxlinux>= 1fa5ae857bb14f6046205171d98506d8112dd74e < 5ca86eae55a2f006e6c1edd2029b2cacb69795155ca86eae55a2f006e6c1edd2029b2cacb6979515
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 2.6.30 < 4.9.3374.9.337
linuxlinux_kernel>= 4.10 < 4.14.3034.14.303
linuxlinux_kernel>= 4.15 < 4.19.2704.19.270
linuxlinux_kernel>= 4.20 < 5.4.2295.4.229
linuxlinux_kernel>= 5.11 < 5.15.865.15.86
linuxlinux_kernel>= 5.16 < 6.0.166.0.16
linuxlinux_kernel>= 5.5 < 5.10.1635.10.163
linuxlinux_kernel>= 6.1 < 6.1.26.1.2

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.