cbcvebase.
CVE-2022-50500
published 2025-10-04

CVE-2022-50500: In the Linux kernel, the following vulnerability has been resolved: netdevsim: fix memory leak in nsim_drv_probe() when nsim_dev_resources_register() failed If…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.13%
2.9th percentile
In the Linux kernel, the following vulnerability has been resolved: netdevsim: fix memory leak in nsim_drv_probe() when nsim_dev_resources_register() failed If some items in nsim_dev_resources_register() fail, memory leak will occur. The following is the memory leak information. unreferenced object 0xffff888074c02600 (size 128): comm "echo", pid 8159, jiffies 4294945184 (age 493.530s) hex dump (first 32 bytes): 40 47 ea 89 ff ff ff ff 01 00 00 00 00 00 00 00 @G.............. ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ................ backtrace: [] kmalloc_trace+0x22/0x60 [] devl_resource_register+0x144/0x4e0 [] nsim_drv_probe+0x37a/0x1260 [] really_probe+0x20b/0xb10 [] __driver_probe_device+0x1b3/0x4a0 [] driver_probe_device+0x49/0x140 [] __device_attach_driver+0x18c/0x2a0 [] bus_for_each_drv+0x151/0x1d0 [] __device_attach+0x1c9/0x4e0 [] bus_probe_device+0x1d5/0x280 [] device_add+0xae0/0x1cb0 [] new_device_store+0x3b6/0x5f0 [] bus_attr_store+0x72/0xa0 [] sysfs_kf_write+0x106/0x160 [] kernfs_fop_write_iter+0x3a8/0x5a0 [] vfs_write+0x8f0/0xc80

Affected

9 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.0.7-1 (bookworm)linux 6.0.7-1 (bookworm)
linuxlinux
linuxlinux>= 37923ed6b8cea94d7d76038e2f72c57a0b45daab < 7c4957fe40e2a628b7cceaf4c9bfb5b701774d057c4957fe40e2a628b7cceaf4c9bfb5b701774d05
linuxlinux>= 37923ed6b8cea94d7d76038e2f72c57a0b45daab < 6b1da9f7126f05e857da6db24c6a04aa7974d6446b1da9f7126f05e857da6db24c6a04aa7974d644
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.0.7-16.0.7-1
linuxlinux_kernel>= 0 < 6.0.7-16.0.7-1
linuxlinux_kernel>= 0 < 6.0.7-16.0.7-1
linuxlinux_kernel>= 4.17 < 6.0.76.0.7

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.