CVE-2022-50521
published 2025-10-07CVE-2022-50521: In the Linux kernel, the following vulnerability has been resolved: platform/x86: mxm-wmi: fix memleak in mxm_wmi_call_mx[ds|mx]() The ACPI buffer memory…
PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.15%
4.4th percentile
In the Linux kernel, the following vulnerability has been resolved:
platform/x86: mxm-wmi: fix memleak in mxm_wmi_call_mx[ds|mx]()
The ACPI buffer memory (out.pointer) returned by wmi_evaluate_method()
is not freed after the call, so it leads to memory leak.
The method results in ACPI buffer is not used, so just pass NULL to
wmi_evaluate_method() which fixes the memory leak.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.4-1 (bookworm) | linux 6.1.4-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 99b38b4acc0d7dbbab443273577cff60080fcfad < 50ac517d6f5348b276f1f663799cf85dce521518 | 50ac517d6f5348b276f1f663799cf85dce521518 |
| linux | linux | >= 99b38b4acc0d7dbbab443273577cff60080fcfad < 5b0f81b0808235967868e01336c976e840217108 | 5b0f81b0808235967868e01336c976e840217108 |
| linux | linux | >= 99b38b4acc0d7dbbab443273577cff60080fcfad < 14bb4bde3b7b2584734b13747b345caeeb41bea3 | 14bb4bde3b7b2584734b13747b345caeeb41bea3 |
| linux | linux | >= 99b38b4acc0d7dbbab443273577cff60080fcfad < 17cd8c46cbec4e6ad593fb9159928b8e7608c11a | 17cd8c46cbec4e6ad593fb9159928b8e7608c11a |
| linux | linux | >= 99b38b4acc0d7dbbab443273577cff60080fcfad < 3cf81501356c9e898ad94b2369ffc805f83f7d7b | 3cf81501356c9e898ad94b2369ffc805f83f7d7b |
| linux | linux | >= 99b38b4acc0d7dbbab443273577cff60080fcfad < 379e7794c5e7485193d25d73614fbbd1e1387f6f | 379e7794c5e7485193d25d73614fbbd1e1387f6f |
| linux | linux | >= 99b38b4acc0d7dbbab443273577cff60080fcfad < 87426ce3bd57ad414b6e2436434ef8128986a9a5 | 87426ce3bd57ad414b6e2436434ef8128986a9a5 |
| linux | linux | >= 99b38b4acc0d7dbbab443273577cff60080fcfad < 727cc0147f5066e359aca65cc6cc5e6d64cc15d8 | 727cc0147f5066e359aca65cc6cc5e6d64cc15d8 |
| linux | linux_kernel | >= 0 < 5.10.178-1 | 5.10.178-1 |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 3.0 < 4.14.303 | 4.14.303 |
| linux | linux_kernel | >= 4.15 < 4.19.270 | 4.19.270 |
| linux | linux_kernel | >= 4.20 < 5.4.229 | 5.4.229 |
| linux | linux_kernel | >= 5.11 < 5.15.86 | 5.15.86 |
| linux | linux_kernel | >= 5.16 < 6.0.16 | 6.0.16 |
| linux | linux_kernel | >= 5.5 < 5.10.163 | 5.10.163 |
| linux | linux_kernel | >= 6.1 < 6.1.2 | 6.1.2 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: platform/x86: mxm-wmi: fix memleak in mxm_wmi_call_mx[ds|mx]()
vendor_redhat·2025-10-07·CVSS 5.5
CVE-2022-50521 [MEDIUM] CWE-772 kernel: platform/x86: mxm-wmi: fix memleak in mxm_wmi_call_mx[ds|mx]()
kernel: platform/x86: mxm-wmi: fix memleak in mxm_wmi_call_mx[ds|mx]()
In the Linux kernel, the following vulnerability has been resolved:
platform/x86: mxm-wmi: fix memleak in mxm_wmi_call_mx[ds|mx]()
The ACPI buffer memory (out.pointer) returned by wmi_evaluate_method()
is not freed after the call, so it leads to memory leak.
The method results in ACPI buffer is not used, so just pass NULL to
wmi_evaluate_method() which fixes the memory leak.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Fix deferred
Package: kernel-rt (Red Hat Enterprise Linux 7) - Fix deferred
Package: kernel (Red Hat Enterprise Linux 8) - Fix deferred
Package: kernel-rt (Red Hat Enterprise L
Debian
CVE-2022-50521: linux - In the Linux kernel, the following vulnerability has been resolved: platform/x8...
vendor_debian·2022·CVSS 5.5
CVE-2022-50521 [MEDIUM] CVE-2022-50521: linux - In the Linux kernel, the following vulnerability has been resolved: platform/x8...
In the Linux kernel, the following vulnerability has been resolved: platform/x86: mxm-wmi: fix memleak in mxm_wmi_call_mx[ds|mx]() The ACPI buffer memory (out.pointer) returned by wmi_evaluate_method() is not freed after the call, so it leads to memory leak. The method results in ACPI buffer is not used, so just pass NULL to wmi_evaluate_method() which fixes the memory leak.
Scope: local
bookworm: resolved (fixed in 6.1.4-1)
bullseye: resolved (fixed in 5.10.178-1)
forky: resolved (fixed in 6.1.4-1)
sid: resolved (fixed in 6.1.4-1)
trixie: resolved (fixed in 6.1.4-1)
VulDB
Linux Kernel up to 6.1.1 wmi_evaluate_method memory leak (Nessus ID 302405 / WID-SEC-2025-2229)
vuldb·2026-04-19·CVSS 5.5
CVE-2022-50521 [MEDIUM] Linux Kernel up to 6.1.1 wmi_evaluate_method memory leak (Nessus ID 302405 / WID-SEC-2025-2229)
A vulnerability classified as critical was found in Linux Kernel up to 6.1.1. The affected element is the function wmi_evaluate_method. The manipulation results in memory leak.
This vulnerability is reported as CVE-2022-50521. The attacker must have access to the local network to execute the attack. No exploit exists.
Upgrading the affected component is advised.
GHSA
GHSA-7v86-rcc3-mqc8: In the Linux kernel, the following vulnerability has been resolved:
platform/x86: mxm-wmi: fix memleak in mxm_wmi_call_mx[ds|mx]()
The ACPI buffer m
ghsa_unreviewed·2025-10-07
CVE-2022-50521 [MEDIUM] CWE-401 GHSA-7v86-rcc3-mqc8: In the Linux kernel, the following vulnerability has been resolved:
platform/x86: mxm-wmi: fix memleak in mxm_wmi_call_mx[ds|mx]()
The ACPI buffer m
In the Linux kernel, the following vulnerability has been resolved:
platform/x86: mxm-wmi: fix memleak in mxm_wmi_call_mx[ds|mx]()
The ACPI buffer memory (out.pointer) returned by wmi_evaluate_method()
is not freed after the call, so it leads to memory leak.
The method results in ACPI buffer is not used, so just pass NULL to
wmi_evaluate_method() which fixes the memory leak.
OSV
CVE-2022-50521: In the Linux kernel, the following vulnerability has been resolved: platform/x86: mxm-wmi: fix memleak in mxm_wmi_call_mx[ds|mx]() The ACPI buffer mem
osv·2025-10-07·CVSS 5.5
CVE-2022-50521 [MEDIUM] CVE-2022-50521: In the Linux kernel, the following vulnerability has been resolved: platform/x86: mxm-wmi: fix memleak in mxm_wmi_call_mx[ds|mx]() The ACPI buffer mem
In the Linux kernel, the following vulnerability has been resolved: platform/x86: mxm-wmi: fix memleak in mxm_wmi_call_mx[ds|mx]() The ACPI buffer memory (out.pointer) returned by wmi_evaluate_method() is not freed after the call, so it leads to memory leak. The method results in ACPI buffer is not used, so just pass NULL to wmi_evaluate_method() which fixes the memory leak.
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/14bb4bde3b7b2584734b13747b345caeeb41bea3https://git.kernel.org/stable/c/17cd8c46cbec4e6ad593fb9159928b8e7608c11ahttps://git.kernel.org/stable/c/379e7794c5e7485193d25d73614fbbd1e1387f6fhttps://git.kernel.org/stable/c/3cf81501356c9e898ad94b2369ffc805f83f7d7bhttps://git.kernel.org/stable/c/50ac517d6f5348b276f1f663799cf85dce521518https://git.kernel.org/stable/c/5b0f81b0808235967868e01336c976e840217108https://git.kernel.org/stable/c/727cc0147f5066e359aca65cc6cc5e6d64cc15d8https://git.kernel.org/stable/c/87426ce3bd57ad414b6e2436434ef8128986a9a5
2025-10-07
Published