CVE-2022-50514Linux vulnerability

6 documents6 sources
Severity
5.5MEDIUMNVD
EPSS
0.0%
top 97.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 7
Latest updateApr 18

Description

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_hid: fix refcount leak on error path When failing to allocate report_desc, opts->refcnt has already been incremented so it needs to be decremented to avoid leaving the options structure permanently locked.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages4 packages

NVDlinux/linux_kernel3.194.19.270+5
Debianlinux/linux_kernel< 5.10.178-1+3
CVEListV5linux/linux21a9476a7ba847e413bf1c144d7c614532aed6dd95412c932b3c9e8cc4431dac4fac8fcd80d54982+7
debiandebian/linux< linux 6.1.4-1 (bookworm)

Patches

🔴Vulnerability Details

3
VulDB
Linux Kernel up to 6.1.1 usb f_hid reference count (WID-SEC-2025-2229)2026-04-18
OSV
CVE-2022-50514: In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_hid: fix refcount leak on error path When failing to allocate repor2025-10-07
GHSA
GHSA-98p2-fhmm-f934: In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_hid: fix refcount leak on error path When failing to allocate rep2025-10-07

📋Vendor Advisories

2
Red Hat
kernel: usb: gadget: f_hid: fix refcount leak on error path2025-10-07
Debian
CVE-2022-50514: linux - In the Linux kernel, the following vulnerability has been resolved: usb: gadget...2022