CVE-2022-50529Missing Release of Memory after Effective Lifetime in Linux

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 97.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 7
Latest updateApr 19

Description

In the Linux kernel, the following vulnerability has been resolved: test_firmware: fix memory leak in test_firmware_init() When misc_register() failed in test_firmware_init(), the memory pointed by test_fw_config->name is not released. The memory leak information is as follows: unreferenced object 0xffff88810a34cb00 (size 32): comm "insmod", pid 7952, jiffies 4294948236 (age 49.060s) hex dump (first 32 bytes): 74 65 73 74 2d 66 69 72 6d 77 61 72 65 2e 62 69 test-firmware.bi 6e 00 00 00 00 00 0

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages4 packages

NVDlinux/linux_kernel4.144.14.303+6
Debianlinux/linux_kernel< 5.10.178-1+3
CVEListV5linux/linuxc92316bf8e94830a0225f2e904cbdbd173768419ed5cbafaf7ce8b86f19998c00eb020c8d49b017f+8
debiandebian/linux< linux 6.1.4-1 (bookworm)

Patches

🔴Vulnerability Details

3
VulDB
Linux Kernel up to 6.1.1 test_firmware_init memory leak (WID-SEC-2025-2229)2026-04-19
OSV
CVE-2022-50529: In the Linux kernel, the following vulnerability has been resolved: test_firmware: fix memory leak in test_firmware_init() When misc_register() failed2025-10-07
GHSA
GHSA-chj4-grxw-4pvw: In the Linux kernel, the following vulnerability has been resolved: test_firmware: fix memory leak in test_firmware_init() When misc_register() fail2025-10-07

📋Vendor Advisories

2
Red Hat
kernel: test_firmware: fix memory leak in test_firmware_init()2025-10-07
Debian
CVE-2022-50529: linux - In the Linux kernel, the following vulnerability has been resolved: test_firmwa...2022