CVE-2022-50522Linux vulnerability

6 documents6 sources
Severity
3.3LOWNVD
EPSS
0.0%
top 97.06%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 7
Latest updateApr 19

Description

In the Linux kernel, the following vulnerability has been resolved: mcb: mcb-parse: fix error handing in chameleon_parse_gdd() If mcb_device_register() returns error in chameleon_parse_gdd(), the refcount of bus and device name are leaked. Fix this by calling put_device() to give up the reference, so they can be released in mcb_release_dev() and kobject_cleanup().

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 1.8 | Impact: 1.4

Affected Packages4 packages

NVDlinux/linux_kernel3.154.9.337+7
Debianlinux/linux_kernel< 5.10.178-1+3
CVEListV5linux/linux3764e82e5150d87b205c10cd78a9c9ab86fbfa51891f606ae0765bc9ca99f5276735be4d338f0255+9
debiandebian/linux< linux 6.1.4-1 (bookworm)

Patches

🔴Vulnerability Details

3
VulDB
Linux Kernel up to 6.1.1 chameleon_parse_gdd reference count (WID-SEC-2025-2229)2026-04-19
GHSA
GHSA-45rc-f9wh-94jr: In the Linux kernel, the following vulnerability has been resolved: mcb: mcb-parse: fix error handing in chameleon_parse_gdd() If mcb_device_registe2025-10-07
OSV
CVE-2022-50522: In the Linux kernel, the following vulnerability has been resolved: mcb: mcb-parse: fix error handing in chameleon_parse_gdd() If mcb_device_register(2025-10-07

📋Vendor Advisories

2
Red Hat
kernel: mcb: mcb-parse: fix error handing in chameleon_parse_gdd()2025-10-07
Debian
CVE-2022-50522: linux - In the Linux kernel, the following vulnerability has been resolved: mcb: mcb-pa...2022