CVE-2022-50522
published 2025-10-07CVE-2022-50522: In the Linux kernel, the following vulnerability has been resolved: mcb: mcb-parse: fix error handing in chameleon_parse_gdd() If mcb_device_register() returns…
PriorityP47low3.3CVSS 3.1
AVLACLPRLUINSUCLINAN
EPSS
0.15%
4.6th percentile
In the Linux kernel, the following vulnerability has been resolved:
mcb: mcb-parse: fix error handing in chameleon_parse_gdd()
If mcb_device_register() returns error in chameleon_parse_gdd(), the refcount
of bus and device name are leaked. Fix this by calling put_device() to give up
the reference, so they can be released in mcb_release_dev() and kobject_cleanup().
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.4-1 (bookworm) | linux 6.1.4-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 3764e82e5150d87b205c10cd78a9c9ab86fbfa51 < 891f606ae0765bc9ca99f5276735be4d338f0255 | 891f606ae0765bc9ca99f5276735be4d338f0255 |
| linux | linux | >= 3764e82e5150d87b205c10cd78a9c9ab86fbfa51 < cf6e70c0ced50b52415ac0c88eba1fb09c500a5a | cf6e70c0ced50b52415ac0c88eba1fb09c500a5a |
| linux | linux | >= 3764e82e5150d87b205c10cd78a9c9ab86fbfa51 < fd85ece416fd7edb945203e59d4cd94952f77e7c | fd85ece416fd7edb945203e59d4cd94952f77e7c |
| linux | linux | >= 3764e82e5150d87b205c10cd78a9c9ab86fbfa51 < 110dc34c9fa33d37f55b394b1199ea6c0ad1ee84 | 110dc34c9fa33d37f55b394b1199ea6c0ad1ee84 |
| linux | linux | >= 3764e82e5150d87b205c10cd78a9c9ab86fbfa51 < 7b289b791a59386dc23a00d3cf17a0db984b40d3 | 7b289b791a59386dc23a00d3cf17a0db984b40d3 |
| linux | linux | >= 3764e82e5150d87b205c10cd78a9c9ab86fbfa51 < 43bfc7c2402a22d3b4eb08c040f274ba2b76461a | 43bfc7c2402a22d3b4eb08c040f274ba2b76461a |
| linux | linux | >= 3764e82e5150d87b205c10cd78a9c9ab86fbfa51 < b948baa29394ec5f4e6ec28486e7d06a76caee91 | b948baa29394ec5f4e6ec28486e7d06a76caee91 |
| linux | linux | >= 3764e82e5150d87b205c10cd78a9c9ab86fbfa51 < 4a9f1a8b3af287581ffb690d0e1593c681729ddb | 4a9f1a8b3af287581ffb690d0e1593c681729ddb |
| linux | linux | >= 3764e82e5150d87b205c10cd78a9c9ab86fbfa51 < 728ac3389296caf68638628c987aeae6c8851e2d | 728ac3389296caf68638628c987aeae6c8851e2d |
| linux | linux_kernel | >= 0 < 5.10.178-1 | 5.10.178-1 |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 3.15 < 4.9.337 | 4.9.337 |
| linux | linux_kernel | >= 4.10 < 4.14.303 | 4.14.303 |
| linux | linux_kernel | >= 4.15 < 4.19.270 | 4.19.270 |
| linux | linux_kernel | >= 4.20 < 5.4.229 | 5.4.229 |
| linux | linux_kernel | >= 5.11 < 5.15.86 | 5.15.86 |
| linux | linux_kernel | >= 5.16 < 6.0.16 | 6.0.16 |
| linux | linux_kernel | >= 5.5 < 5.10.163 | 5.10.163 |
| linux | linux_kernel | >= 6.1 < 6.1.2 | 6.1.2 |
CVSS provenance
nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
osv3.3LOW
vendor_debian3.3LOW
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: mcb: mcb-parse: fix error handing in chameleon_parse_gdd()
vendor_redhat·2025-10-07·CVSS 3.3
CVE-2022-50522 [LOW] kernel: mcb: mcb-parse: fix error handing in chameleon_parse_gdd()
kernel: mcb: mcb-parse: fix error handing in chameleon_parse_gdd()
In the Linux kernel, the following vulnerability has been resolved:
mcb: mcb-parse: fix error handing in chameleon_parse_gdd()
If mcb_device_register() returns error in chameleon_parse_gdd(), the refcount
of bus and device name are leaked. Fix this by calling put_device() to give up
the reference, so they can be released in mcb_release_dev() and kobject_cleanup().
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 8) - Not a
Debian
CVE-2022-50522: linux - In the Linux kernel, the following vulnerability has been resolved: mcb: mcb-pa...
vendor_debian·2022·CVSS 3.3
CVE-2022-50522 [LOW] CVE-2022-50522: linux - In the Linux kernel, the following vulnerability has been resolved: mcb: mcb-pa...
In the Linux kernel, the following vulnerability has been resolved: mcb: mcb-parse: fix error handing in chameleon_parse_gdd() If mcb_device_register() returns error in chameleon_parse_gdd(), the refcount of bus and device name are leaked. Fix this by calling put_device() to give up the reference, so they can be released in mcb_release_dev() and kobject_cleanup().
Scope: local
bookworm: resolved (fixed in 6.1.4-1)
bullseye: resolved (fixed in 5.10.178-1)
forky: resolved (fixed in 6.1.4-1)
sid: resolved (fixed in 6.1.4-1)
trixie: resolved (fixed in 6.1.4-1)
VulDB
Linux Kernel up to 6.1.1 chameleon_parse_gdd reference count (WID-SEC-2025-2229)
vuldb·2026-04-19·CVSS 3.3
CVE-2022-50522 [LOW] Linux Kernel up to 6.1.1 chameleon_parse_gdd reference count (WID-SEC-2025-2229)
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.1.1. The impacted element is the function chameleon_parse_gdd. This manipulation causes improper update of reference count.
This vulnerability appears as CVE-2022-50522. The attacker needs to be present on the local network. There is no available exploit.
It is advisable to upgrade the affected component.
GHSA
GHSA-45rc-f9wh-94jr: In the Linux kernel, the following vulnerability has been resolved:
mcb: mcb-parse: fix error handing in chameleon_parse_gdd()
If mcb_device_registe
ghsa_unreviewed·2025-10-07
CVE-2022-50522 [LOW] GHSA-45rc-f9wh-94jr: In the Linux kernel, the following vulnerability has been resolved:
mcb: mcb-parse: fix error handing in chameleon_parse_gdd()
If mcb_device_registe
In the Linux kernel, the following vulnerability has been resolved:
mcb: mcb-parse: fix error handing in chameleon_parse_gdd()
If mcb_device_register() returns error in chameleon_parse_gdd(), the refcount
of bus and device name are leaked. Fix this by calling put_device() to give up
the reference, so they can be released in mcb_release_dev() and kobject_cleanup().
OSV
CVE-2022-50522: In the Linux kernel, the following vulnerability has been resolved: mcb: mcb-parse: fix error handing in chameleon_parse_gdd() If mcb_device_register(
osv·2025-10-07·CVSS 3.3
CVE-2022-50522 [LOW] CVE-2022-50522: In the Linux kernel, the following vulnerability has been resolved: mcb: mcb-parse: fix error handing in chameleon_parse_gdd() If mcb_device_register(
In the Linux kernel, the following vulnerability has been resolved: mcb: mcb-parse: fix error handing in chameleon_parse_gdd() If mcb_device_register() returns error in chameleon_parse_gdd(), the refcount of bus and device name are leaked. Fix this by calling put_device() to give up the reference, so they can be released in mcb_release_dev() and kobject_cleanup().
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/110dc34c9fa33d37f55b394b1199ea6c0ad1ee84https://git.kernel.org/stable/c/43bfc7c2402a22d3b4eb08c040f274ba2b76461ahttps://git.kernel.org/stable/c/4a9f1a8b3af287581ffb690d0e1593c681729ddbhttps://git.kernel.org/stable/c/728ac3389296caf68638628c987aeae6c8851e2dhttps://git.kernel.org/stable/c/7b289b791a59386dc23a00d3cf17a0db984b40d3https://git.kernel.org/stable/c/891f606ae0765bc9ca99f5276735be4d338f0255https://git.kernel.org/stable/c/b948baa29394ec5f4e6ec28486e7d06a76caee91https://git.kernel.org/stable/c/cf6e70c0ced50b52415ac0c88eba1fb09c500a5ahttps://git.kernel.org/stable/c/fd85ece416fd7edb945203e59d4cd94952f77e7c
2025-10-07
Published