CVE-2022-50529
published 2025-10-07CVE-2022-50529: In the Linux kernel, the following vulnerability has been resolved: test_firmware: fix memory leak in test_firmware_init() When misc_register() failed in…
PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.15%
4.4th percentile
In the Linux kernel, the following vulnerability has been resolved:
test_firmware: fix memory leak in test_firmware_init()
When misc_register() failed in test_firmware_init(), the memory pointed
by test_fw_config->name is not released. The memory leak information is
as follows:
unreferenced object 0xffff88810a34cb00 (size 32):
comm "insmod", pid 7952, jiffies 4294948236 (age 49.060s)
hex dump (first 32 bytes):
74 65 73 74 2d 66 69 72 6d 77 61 72 65 2e 62 69 test-firmware.bi
6e 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 n...............
backtrace:
[] __kmalloc_node_track_caller+0x4b/0xc0
[] kstrndup+0x46/0xc0
[] __test_firmware_config_init+0x29/0x380 [test_firmware]
[] 0xffffffffa040f068
[] do_one_initcall+0x141/0x780
[] do_init_module+0x1c3/0x630
[] load_module+0x623e/0x76a0
[] __do_sys_finit_module+0x181/0x240
[] do_syscall_64+0x39/0xb0
[] entry_SYSCALL_64_after_hwframe+0x63/0xcd
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.4-1 (bookworm) | linux 6.1.4-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= c92316bf8e94830a0225f2e904cbdbd173768419 < ed5cbafaf7ce8b86f19998c00eb020c8d49b017f | ed5cbafaf7ce8b86f19998c00eb020c8d49b017f |
| linux | linux | >= c92316bf8e94830a0225f2e904cbdbd173768419 < 04dd47a2e169f2d4489636afa07ff0469aab49ab | 04dd47a2e169f2d4489636afa07ff0469aab49ab |
| linux | linux | >= c92316bf8e94830a0225f2e904cbdbd173768419 < 628de998a3abfffb3f9677d2fb39a1d5dcb32fdb | 628de998a3abfffb3f9677d2fb39a1d5dcb32fdb |
| linux | linux | >= c92316bf8e94830a0225f2e904cbdbd173768419 < 0b5a89e8bce1ea43687742b4de8e216189ff94ac | 0b5a89e8bce1ea43687742b4de8e216189ff94ac |
| linux | linux | >= c92316bf8e94830a0225f2e904cbdbd173768419 < 357379d504c0c8b0834e206ad8c49e4b3c98ed4d | 357379d504c0c8b0834e206ad8c49e4b3c98ed4d |
| linux | linux | >= c92316bf8e94830a0225f2e904cbdbd173768419 < 8d8c1d6a430f0aadb80036e2b1bc0a05f9fad247 | 8d8c1d6a430f0aadb80036e2b1bc0a05f9fad247 |
| linux | linux | >= c92316bf8e94830a0225f2e904cbdbd173768419 < 6dd5fbd243f19f087dc79481acb7d69fb57fea2c | 6dd5fbd243f19f087dc79481acb7d69fb57fea2c |
| linux | linux | >= c92316bf8e94830a0225f2e904cbdbd173768419 < 7610615e8cdb3f6f5bbd9d8e7a5d8a63e3cabf2e | 7610615e8cdb3f6f5bbd9d8e7a5d8a63e3cabf2e |
| linux | linux_kernel | >= 0 < 5.10.178-1 | 5.10.178-1 |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 0 < 6.1.4-1 | 6.1.4-1 |
| linux | linux_kernel | >= 4.14 < 4.14.303 | 4.14.303 |
| linux | linux_kernel | >= 4.15 < 4.19.270 | 4.19.270 |
| linux | linux_kernel | >= 4.20 < 5.4.229 | 5.4.229 |
| linux | linux_kernel | >= 5.11 < 5.15.86 | 5.15.86 |
| linux | linux_kernel | >= 5.16 < 6.0.16 | 6.0.16 |
| linux | linux_kernel | >= 5.5 < 5.10.163 | 5.10.163 |
| linux | linux_kernel | >= 6.1 < 6.1.2 | 6.1.2 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Linux Kernel up to 6.1.1 test_firmware_init memory leak (WID-SEC-2025-2229)
vuldb·2026-04-19·CVSS 5.5
CVE-2022-50529 [MEDIUM] Linux Kernel up to 6.1.1 test_firmware_init memory leak (WID-SEC-2025-2229)
A vulnerability labeled as critical has been found in Linux Kernel up to 6.1.1. Affected is the function test_firmware_init. The manipulation results in memory leak.
This vulnerability is cataloged as CVE-2022-50529. The attack must originate from the local network. There is no exploit available.
The affected component should be upgraded.
OSV
CVE-2022-50529: In the Linux kernel, the following vulnerability has been resolved: test_firmware: fix memory leak in test_firmware_init() When misc_register() failed
osv·2025-10-07·CVSS 5.5
CVE-2022-50529 [MEDIUM] CVE-2022-50529: In the Linux kernel, the following vulnerability has been resolved: test_firmware: fix memory leak in test_firmware_init() When misc_register() failed
In the Linux kernel, the following vulnerability has been resolved: test_firmware: fix memory leak in test_firmware_init() When misc_register() failed in test_firmware_init(), the memory pointed by test_fw_config->name is not released. The memory leak information is as follows: unreferenced object 0xffff88810a34cb00 (size 32): comm "insmod", pid 7952, jiffies 4294948236 (age 49.060s) hex dump (first 32 bytes): 74 65 73 74 2d 66 69 72 6d 77 61 72 65 2e 62 69 test-firmware.bi 6e 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 n............... backtrace: [] __kmalloc_node_track_caller+0x4b/0xc0 [] kstrndup+0x46/0xc0 [] __test_firmware_config_init+0x29/0x380 [test_firmware] [] 0xffffffffa040f068 [] do_one_initcall+0x141/0x780 [] do_init_module+0x1c3/0x630 [] load_module+0x623e/0x76a0 [] __do_sys_
GHSA
GHSA-chj4-grxw-4pvw: In the Linux kernel, the following vulnerability has been resolved:
test_firmware: fix memory leak in test_firmware_init()
When misc_register() fail
ghsa_unreviewed·2025-10-07
CVE-2022-50529 [MEDIUM] CWE-401 GHSA-chj4-grxw-4pvw: In the Linux kernel, the following vulnerability has been resolved:
test_firmware: fix memory leak in test_firmware_init()
When misc_register() fail
In the Linux kernel, the following vulnerability has been resolved:
test_firmware: fix memory leak in test_firmware_init()
When misc_register() failed in test_firmware_init(), the memory pointed
by test_fw_config->name is not released. The memory leak information is
as follows:
unreferenced object 0xffff88810a34cb00 (size 32):
comm "insmod", pid 7952, jiffies 4294948236 (age 49.060s)
hex dump (first 32 bytes):
74 65 73 74 2d 66 69 72 6d 77 61 72 65 2e 62 69 test-firmware.bi
6e 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 n...............
backtrace:
[] __kmalloc_node_track_caller+0x4b/0xc0
[] kstrndup+0x46/0xc0
[] __test_firmware_config_init+0x29/0x380 [test_firmware]
[] 0xffffffffa040f068
[] do_one_initcall+0x141/0x780
[] do_init_module+0x1c3/0x630
[] load_module+0x623e/0x76a0
[] __do_sy
Red Hat
kernel: test_firmware: fix memory leak in test_firmware_init()
vendor_redhat·2025-10-07·CVSS 5.5
CVE-2022-50529 [MEDIUM] kernel: test_firmware: fix memory leak in test_firmware_init()
kernel: test_firmware: fix memory leak in test_firmware_init()
In the Linux kernel, the following vulnerability has been resolved:
test_firmware: fix memory leak in test_firmware_init()
When misc_register() failed in test_firmware_init(), the memory pointed
by test_fw_config->name is not released. The memory leak information is
as follows:
unreferenced object 0xffff88810a34cb00 (size 32):
comm "insmod", pid 7952, jiffies 4294948236 (age 49.060s)
hex dump (first 32 bytes):
74 65 73 74 2d 66 69 72 6d 77 61 72 65 2e 62 69 test-firmware.bi
6e 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 n...............
backtrace:
[] __kmalloc_node_track_caller+0x4b/0xc0
[] kstrndup+0x46/0xc0
[] __test_firmware_config_init+0x29/0x380 [test_firmware]
[] 0xffffffffa040f068
[] do_one_initcall+0x141/0x780
[] do_i
Debian
CVE-2022-50529: linux - In the Linux kernel, the following vulnerability has been resolved: test_firmwa...
vendor_debian·2022·CVSS 5.5
CVE-2022-50529 [MEDIUM] CVE-2022-50529: linux - In the Linux kernel, the following vulnerability has been resolved: test_firmwa...
In the Linux kernel, the following vulnerability has been resolved: test_firmware: fix memory leak in test_firmware_init() When misc_register() failed in test_firmware_init(), the memory pointed by test_fw_config->name is not released. The memory leak information is as follows: unreferenced object 0xffff88810a34cb00 (size 32): comm "insmod", pid 7952, jiffies 4294948236 (age 49.060s) hex dump (first 32 bytes): 74 65 73 74 2d 66 69 72 6d 77 61 72 65 2e 62 69 test-firmware.bi 6e 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 n............... backtrace: [] __kmalloc_node_track_caller+0x4b/0xc0 [] kstrndup+0x46/0xc0 [] __test_firmware_config_init+0x29/0x380 [test_firmware] [] 0xffffffffa040f068 [] do_one_initcall+0x141/0x780 [] do_init_module+0x1c3/0x630 [] load_module+0x623e/0x76a0 [] __do_sys_
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/04dd47a2e169f2d4489636afa07ff0469aab49abhttps://git.kernel.org/stable/c/0b5a89e8bce1ea43687742b4de8e216189ff94achttps://git.kernel.org/stable/c/357379d504c0c8b0834e206ad8c49e4b3c98ed4dhttps://git.kernel.org/stable/c/628de998a3abfffb3f9677d2fb39a1d5dcb32fdbhttps://git.kernel.org/stable/c/6dd5fbd243f19f087dc79481acb7d69fb57fea2chttps://git.kernel.org/stable/c/7610615e8cdb3f6f5bbd9d8e7a5d8a63e3cabf2ehttps://git.kernel.org/stable/c/8d8c1d6a430f0aadb80036e2b1bc0a05f9fad247https://git.kernel.org/stable/c/ed5cbafaf7ce8b86f19998c00eb020c8d49b017f
2025-10-07
Published