cbcvebase.
CVE-2022-50529
published 2025-10-07

CVE-2022-50529: In the Linux kernel, the following vulnerability has been resolved: test_firmware: fix memory leak in test_firmware_init() When misc_register() failed in…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.15%
4.4th percentile
In the Linux kernel, the following vulnerability has been resolved: test_firmware: fix memory leak in test_firmware_init() When misc_register() failed in test_firmware_init(), the memory pointed by test_fw_config->name is not released. The memory leak information is as follows: unreferenced object 0xffff88810a34cb00 (size 32): comm "insmod", pid 7952, jiffies 4294948236 (age 49.060s) hex dump (first 32 bytes): 74 65 73 74 2d 66 69 72 6d 77 61 72 65 2e 62 69 test-firmware.bi 6e 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 n............... backtrace: [] __kmalloc_node_track_caller+0x4b/0xc0 [] kstrndup+0x46/0xc0 [] __test_firmware_config_init+0x29/0x380 [test_firmware] [] 0xffffffffa040f068 [] do_one_initcall+0x141/0x780 [] do_init_module+0x1c3/0x630 [] load_module+0x623e/0x76a0 [] __do_sys_finit_module+0x181/0x240 [] do_syscall_64+0x39/0xb0 [] entry_SYSCALL_64_after_hwframe+0x63/0xcd

Affected

21 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.4-1 (bookworm)linux 6.1.4-1 (bookworm)
linuxlinux
linuxlinux>= c92316bf8e94830a0225f2e904cbdbd173768419 < ed5cbafaf7ce8b86f19998c00eb020c8d49b017fed5cbafaf7ce8b86f19998c00eb020c8d49b017f
linuxlinux>= c92316bf8e94830a0225f2e904cbdbd173768419 < 04dd47a2e169f2d4489636afa07ff0469aab49ab04dd47a2e169f2d4489636afa07ff0469aab49ab
linuxlinux>= c92316bf8e94830a0225f2e904cbdbd173768419 < 628de998a3abfffb3f9677d2fb39a1d5dcb32fdb628de998a3abfffb3f9677d2fb39a1d5dcb32fdb
linuxlinux>= c92316bf8e94830a0225f2e904cbdbd173768419 < 0b5a89e8bce1ea43687742b4de8e216189ff94ac0b5a89e8bce1ea43687742b4de8e216189ff94ac
linuxlinux>= c92316bf8e94830a0225f2e904cbdbd173768419 < 357379d504c0c8b0834e206ad8c49e4b3c98ed4d357379d504c0c8b0834e206ad8c49e4b3c98ed4d
linuxlinux>= c92316bf8e94830a0225f2e904cbdbd173768419 < 8d8c1d6a430f0aadb80036e2b1bc0a05f9fad2478d8c1d6a430f0aadb80036e2b1bc0a05f9fad247
linuxlinux>= c92316bf8e94830a0225f2e904cbdbd173768419 < 6dd5fbd243f19f087dc79481acb7d69fb57fea2c6dd5fbd243f19f087dc79481acb7d69fb57fea2c
linuxlinux>= c92316bf8e94830a0225f2e904cbdbd173768419 < 7610615e8cdb3f6f5bbd9d8e7a5d8a63e3cabf2e7610615e8cdb3f6f5bbd9d8e7a5d8a63e3cabf2e
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 0 < 6.1.4-16.1.4-1
linuxlinux_kernel>= 4.14 < 4.14.3034.14.303
linuxlinux_kernel>= 4.15 < 4.19.2704.19.270
linuxlinux_kernel>= 4.20 < 5.4.2295.4.229
linuxlinux_kernel>= 5.11 < 5.15.865.15.86
linuxlinux_kernel>= 5.16 < 6.0.166.0.16
linuxlinux_kernel>= 5.5 < 5.10.1635.10.163
linuxlinux_kernel>= 6.1 < 6.1.26.1.2

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.